<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2019-10-10" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 https://scap.nist.gov/schema/nvd/nvd-cve-feed_1.2.1.xsd">
  <entry type="CVE" name="CVE-1999-0001" seq="1999-0001" published="1999-12-30" modified="2010-12-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.openbsd.org/errata23.html#tcpfix">http://www.openbsd.org/errata23.html#tcpfix</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.5.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.5"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0002" seq="1999-0002" published="1998-10-12" modified="2009-01-26" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/121" adv="1" patch="1">121</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="1.1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="3.0.3"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0003" seq="1999-0003" published="1998-04-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref>
    </refs>
    <vuln_soft>
      <prod name="ted_cde" vendor="tritreal">
        <vers num="4.3"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.02"/>
        <vers num="10.03"/>
        <vers num="11.00"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0004" seq="1999-0004" published="1997-12-16" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-008">MS98-008</ref>
    </refs>
    <vuln_soft>
      <prod name="dtmail" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="pine" vendor="university_of_washington">
        <vers num="4.02"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0005" seq="1999-0005" published="1998-07-20" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Arbitrary command execution via IMAP buffer overflow in authenticate command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref>
    </refs>
    <vuln_soft>
      <prod name="messaging_server" vendor="netscape">
        <vers num="3.55"/>
      </prod>
      <prod name="imap" vendor="university_of_washington">
        <vers num="10.234"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0006" seq="1999-0006" published="1998-07-14" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0007" seq="1999-0007" published="1998-06-26" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Information from SSL-encrypted sessions via PKCS #1.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-002">MS98-002</ref>
    </refs>
    <vuln_soft>
      <prod name="stonghold_web_server" vendor="c2net">
        <vers num="2.0.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
      <prod name="certificate_server" vendor="netscape">
        <vers num="1.0" edition="patch1"/>
      </prod>
      <prod name="collabra_server" vendor="netscape">
        <vers num="3.5.2"/>
      </prod>
      <prod name="directory_server" vendor="netscape">
        <vers num="1.3" edition="patch5"/>
        <vers num="3.1" edition="patch1"/>
        <vers num="3.12"/>
      </prod>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="2.0"/>
        <vers num="3.0.1b"/>
        <vers num="3.5.1"/>
      </prod>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num="3.01b"/>
      </prod>
      <prod name="messaging_server" vendor="netscape">
        <vers num="3.54"/>
      </prod>
      <prod name="proxy_server" vendor="netscape">
        <vers num="3.5.1"/>
      </prod>
      <prod name="secure_webserver" vendor="open_market">
        <vers num="2.1"/>
      </prod>
      <prod name="ssleay" vendor="ssleay">
        <vers num="0.6.6"/>
        <vers num="0.8.1"/>
        <vers num="0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0008" seq="1999-0008" published="1998-06-08" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in NIS+, in Sun's rpc.nisd program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.34"/>
        <vers num="11.00"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0009" seq="1999-0009" published="1998-04-08" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
    </refs>
    <vuln_soft>
      <prod name="dg_ux" vendor="data_general">
        <vers num="5.4_3.0"/>
        <vers num="5.4_3.1"/>
        <vers num="5.4_4.1"/>
        <vers num="5.4_4.11"/>
      </prod>
      <prod name="bind" vendor="isc">
        <vers num="4.9.6"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num="64"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1"/>
        <vers num="7.0"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.1t"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4b"/>
        <vers num="4.0.4t"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5_iop"/>
        <vers num="4.0.5_ipr"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.5d"/>
        <vers num="4.0.5e"/>
        <vers num="4.0.5f"/>
        <vers num="4.0.5g"/>
        <vers num="4.0.5h"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0010" seq="1999-0010" published="1998-04-08" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
    </refs>
    <vuln_soft>
      <prod name="dg_ux" vendor="data_general">
        <vers num="y2k_patchr4.11mu05"/>
        <vers num="y2k_patchr4.12mu03"/>
        <vers num="y2k_patchr4.20mu01"/>
        <vers num="y2k_patchr4.20mu02"/>
        <vers num="y2k_patchr4.20mu03"/>
      </prod>
      <prod name="bind" vendor="isc">
        <vers num="4.9"/>
        <vers num="8"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num="11"/>
        <vers num="13"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2v4"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1"/>
        <vers num="7.0"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0011" seq="1999-0011" published="1998-04-08" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
    </refs>
    <vuln_soft>
      <prod name="dg_ux" vendor="data_general">
        <vers num="y2k_patchr4.11mu05"/>
        <vers num="y2k_patchr4.12mu03"/>
        <vers num="y2k_patchr4.20mu01"/>
        <vers num="y2k_patchr4.20mu02"/>
        <vers num="y2k_patchr4.20mu03"/>
      </prod>
      <prod name="bind" vendor="isc">
        <vers num="4.9"/>
        <vers num="8"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num="11"/>
        <vers num="13"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2v4"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1"/>
        <vers num="7.0"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0012" seq="1999-0012" published="1998-02-06" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="personal_web_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.0"/>
      </prod>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num="2.01"/>
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0013" seq="1999-0013" published="1998-01-22" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.13"/>
        <vers num="1.2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0014" seq="1999-0014" published="1998-01-21" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unauthorized privileged access or denial of service via dtappgather program in CDE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref>
    </refs>
    <vuln_soft>
      <prod name="cde" vendor="cde">
        <vers num="1.01"/>
        <vers num="1.01_x86"/>
        <vers num="1.02"/>
        <vers num="1.02_x86"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
      <prod name="vvos" vendor="hp">
        <vers num="10.24"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0015" seq="1999-0015" published="1997-12-16" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Teardrop IP denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5579">oval:org.mitre.oval:def:5579</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="9.01"/>
        <vers num="9.03"/>
        <vers num="9.04"/>
        <vers num="9.05"/>
        <vers num="9.07"/>
        <vers num="10"/>
        <vers num="10.01"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.30"/>
        <vers num="11.00"/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num="0.0a"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1" edition="sp1"/>
        <vers num="3.5.1" edition="sp2"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0016" seq="1999-0016" published="1997-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Land IP denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref>
    </refs>
    <vuln_soft>
      <prod name="inet" vendor="gnu">
        <vers num="5.01"/>
      </prod>
      <prod name="winsock" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="7000"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="9.01"/>
        <vers num="9.03"/>
        <vers num="9.04"/>
        <vers num="9.05"/>
        <vers num="9.07"/>
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.30"/>
        <vers num="11.00"/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0017" seq="1999-0017" published="1997-12-10" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inet" vendor="gnu">
        <vers num="5.01"/>
        <vers num="6.01"/>
        <vers num="6.02"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.2"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.1.0"/>
        <vers num="2.1.7"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.4"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1"/>
      </prod>
      <prod name="reliant_unix" vendor="siemens">
        <vers num=""/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4" edition=":x86"/>
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0018" seq="1999-0018" published="1997-12-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in statd allows root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/127" patch="1">127</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0019" seq="1999-0019" published="1996-04-24" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Delete or create a file via rpc.statd, due to invalid information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref>
    </refs>
    <vuln_soft>
      <prod name="dg_ux" vendor="data_general">
        <vers num="4.11"/>
      </prod>
      <prod name="mp-ras" vendor="ncr">
        <vers num="2.03"/>
        <vers num="3.0"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
      </prod>
      <prod name="cx_ux" vendor="nighthawk">
        <vers num=""/>
      </prod>
      <prod name="powerux" vendor="nighthawk">
        <vers num=""/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="2"/>
        <vers num="3"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="3.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.1"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4" edition=":x86"/>
        <vers num="5.5" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0020" seq="1999-0020" published="1999-01-01" modified="2008-09-09" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0032.  Reason: This candidate is a duplicate of CVE-1999-0032.  Notes: All CVE users should reference CVE-1999-0032 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0021" seq="1999-0021" published="1997-11-05" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref>
    </refs>
    <vuln_soft>
      <prod name="wwwcount" vendor="muhammad_a._muquit">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0022" seq="1999-0022" published="1996-07-03" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Local user gains root privileges via buffer overflow in rdist, via expstr() function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="1.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="4.1.3"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3u1"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0023" seq="1999-0023" published="1996-07-24" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Local user gains root privileges via buffer overflow in rdist, via lookup() function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inet" vendor="inet">
        <vers num="5.01"/>
        <vers num="6.01"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num=""/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.2"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num="1.0"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="2.0"/>
        <vers num="5.0"/>
        <vers num="5.0.2"/>
      </prod>
      <prod name="tcp_ip" vendor="sco">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0024" seq="1999-0024" published="1997-08-13" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">DNS cache poisoning via BIND, by predictable query IDs.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="4.9.5"/>
        <vers num="8.1"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num="64"/>
      </prod>
      <prod name="ews-ux_v" vendor="nec">
        <vers num="4.2"/>
        <vers num="4.2mp"/>
      </prod>
      <prod name="up-ux_v" vendor="nec">
        <vers num="4.2mp"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2v4"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0025" seq="1999-0025" published="1997-07-16" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">root privileges via buffer overflow in df command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/440">df-bo(440)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0026" seq="1999-0026" published="1997-07-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">root privileges via buffer overflow in pset command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0027" seq="1999-0027" published="1997-07-16" modified="2009-02-25" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">root privileges via buffer overflow in eject command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0028" seq="1999-0028" published="1997-07-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0029" seq="1999-0029" published="1997-07-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">root privileges via buffer overflow in ordist command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0030" seq="1999-0030" published="1997-07-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">root privileges via buffer overflow in xlock command on SGI IRIX systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0031" seq="1999-0031" published="1997-07-08" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="communicator" vendor="netscape">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0032" seq="1999-0032" published="1996-10-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
      </prod>
      <prod name="nextstep" vendor="next">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0033" seq="1999-0033" published="1997-06-12" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Command execution in Sun systems via buffer overflow in the at program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="mp-ras" vendor="ncr">
        <vers num="3.0"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num=""/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="3.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1"/>
        <vers num="3.2v4"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4" edition=":x86"/>
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0034" seq="1999-0034" published="1997-05-29" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="perl" vendor="larry_wall">
        <vers num="5.3"/>
      </prod>
      <prod name="freeware" vendor="sgi">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0035" seq="1999-0035" published="1997-05-29" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inet" vendor="gnu">
        <vers num="5.01"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0036" seq="1999-0036" published="1997-05-26" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/557">sgi-lockout(557)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0037" seq="1999-0037" published="1997-05-21" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0038" seq="1999-0038" published="1997-04-26" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xlock program allows local users to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="dg_ux" vendor="data_general">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="0.93"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0039" seq="1999-0039" published="1997-05-06" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/333">http-sgi-webdist(333)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0040" seq="1999-0040" published="1997-05-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="9.01"/>
        <vers num="9.10"/>
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num="64"/>
      </prod>
      <prod name="ews-ux_v" vendor="nec">
        <vers num="4.2"/>
        <vers num="4.2mp"/>
      </prod>
      <prod name="up-ux_v" vendor="nec">
        <vers num="4.2mp"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0041" seq="1999-0041" published="1997-02-13" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in NLS (Natural Language Service).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="libc" vendor="gnu">
        <vers num="5.0.9"/>
        <vers num="5.2.18"/>
        <vers num="5.3.12"/>
      </prod>
      <prod name="unicos" vendor="cray">
        <vers num="1.5" edition=":mk"/>
        <vers num="9.0"/>
        <vers num="9.2"/>
      </prod>
      <prod name="unicos_max" vendor="cray">
        <vers num="1.3"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0042" seq="1999-0042" published="1997-04-07" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in University of Washington's implementation of IMAP and POP servers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="imap" vendor="university_of_washington">
        <vers num="4"/>
      </prod>
      <prod name="pop" vendor="university_of_washington">
        <vers num="3"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.2.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="2.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0043" seq="1999-0043" published="1996-12-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="1.4sec"/>
        <vers num="1.4sec2"/>
        <vers num="1.4unoff3"/>
        <vers num="1.4unoff4"/>
        <vers num="1.5"/>
      </prod>
      <prod name="news_server" vendor="netscape">
        <vers num="1.1"/>
      </prod>
      <prod name="goah_intrasv" vendor="nec">
        <vers num="1.1"/>
      </prod>
      <prod name="goah_networksv" vendor="nec">
        <vers num="1.2"/>
        <vers num="2.2"/>
        <vers num="3.1"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0044" seq="1999-0044" published="1996-12-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0045" seq="1999-0045" published="1996-12-10" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">List of arbitrary files on Web host via nph-test-cgi script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="0.8.11"/>
        <vers num="0.8.14"/>
        <vers num="1.0"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.1"/>
      </prod>
      <prod name="commerce_server" vendor="netscape">
        <vers num="1.12"/>
      </prod>
      <prod name="communications_server" vendor="netscape">
        <vers num="1.1"/>
        <vers num="1.12"/>
      </prod>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="2.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0046" seq="1999-0046" published="1997-02-06" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow of rlogin program using TERM environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="dg_ux" vendor="data_general">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="1.1"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="0.93"/>
      </prod>
      <prod name="ultrix" vendor="digital">
        <vers num="2.2"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.3a"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num="3.2g"/>
        <vers num="4.0"/>
        <vers num="4.0a"/>
        <vers num="4.0b"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="nextstep" vendor="next">
        <vers num="1.0"/>
        <vers num="1.0a"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="4.0"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0047" seq="1999-0047" published="1997-01-28" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.8.3"/>
        <vers num="8.8.4"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0048" seq="1999-0048" published="1997-01-27" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref>
    </refs>
    <vuln_soft>
      <prod name="netkit" vendor="debian">
        <vers num="0.07"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num=""/>
      </prod>
      <prod name="ews-ux_v" vendor="nec">
        <vers num=""/>
      </prod>
      <prod name="up-ux_v" vendor="nec">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0049" seq="1999-0049" published="1997-01-08" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Csetup under IRIX allows arbitrary file creation or overwriting.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0050" seq="1999-0050" published="1996-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in HP-UX newgrp program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="9.01"/>
        <vers num="9.03"/>
        <vers num="9.04"/>
        <vers num="9.05"/>
        <vers num="9.06"/>
        <vers num="9.07"/>
        <vers num="9.08"/>
        <vers num="9.09"/>
        <vers num="9.10"/>
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0051" seq="1999-0051" published="1997-01-06" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="flexlm" vendor="globetrotter">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
      <prod name="license_oeo" vendor="sgi">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.1t"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.4b"/>
        <vers num="4.0.4t"/>
        <vers num="4.0.5"/>
        <vers num="4.0.5_iop"/>
        <vers num="4.0.5_ipr"/>
        <vers num="4.0.5a"/>
        <vers num="4.0.5d"/>
        <vers num="4.0.5e"/>
        <vers num="4.0.5f"/>
        <vers num="4.0.5g"/>
        <vers num="4.0.5h"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="4.1.4jl"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0052" seq="1999-0052" published="1998-11-04" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1389">freebsd-ip-frag-dos(1389)</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="4.0"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.8"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0053" seq="1999-0053" published="1998-10-13" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">TCP RST denial of service in FreeBSD.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0054" seq="1999-0054" published="1998-06-10" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sun's ftpd daemon can be subjected to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0055" seq="1999-0055" published="1998-05-14" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in Sun libnsl allow root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0056" seq="1999-0056" published="1998-09-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Sun's ping program can give root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0057" seq="1999-0057" published="1998-11-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vacation program allows command execution by remote users through a sendmail command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref>
    </refs>
    <vuln_soft>
      <prod name="vacation" vendor="eric_allman">
        <vers num=""/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10.00"/>
        <vers num="10.09"/>
        <vers num="10.24"/>
      </prod>
      <prod name="vvos" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num=""/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0058" seq="1999-0058" published="1997-04-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in PHP cgi program, php.cgi allows shell access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="1.0"/>
        <vers num="2.0b10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0059" seq="1999-0059" published="1997-07-14" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">IRIX fam service allows an attacker to obtain a list of all files on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/325">irix-fam(325)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0060" seq="1999-0060" published="1998-03-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ascend_max_router" vendor="lucent">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="ascend_pipeline_router" vendor="lucent">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
      <prod name="ascend_tnt_router" vendor="lucent">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0061" seq="1999-0061" published="1997-10-02" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num=""/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0062" seq="1999-0062" published="1998-08-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0063" seq="1999-0063" published="1999-01-11" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.3aa"/>
        <vers num="11.3db"/>
        <vers num="12.0"/>
        <vers num="12.0(1)w"/>
        <vers num="12.0(1)xa3"/>
        <vers num="12.0(1)xb"/>
        <vers num="12.0(1)xe"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0db"/>
        <vers num="12.0s"/>
        <vers num="12.0t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0064" seq="1999-0064" published="1997-05-26" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX lquerylv program gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0065" seq="1999-0065" published="1998-08-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0066" seq="1999-0066" published="1995-07-31" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AnyForm CGI remote execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref>
    </refs>
    <vuln_soft>
      <prod name="anyform" vendor="john_s._roberts">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0067" seq="1999-0067" published="1996-03-20" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">phf CGI program allows remote command execution through shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.0.3"/>
      </prod>
      <prod name="ncsa_httpd" vendor="ncsa">
        <vers num="1.5a" edition=":export"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0068" seq="1999-0068" published="1997-10-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CGI PHP mylog script allows an attacker to read any file on the target server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="2.0b10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0069" seq="1999-0069" published="1998-04-29" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris ufsrestore buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0070" seq="1999-0070" published="1996-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">test-cgi program allows an attacker to list files on the server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
      <prod name="ncsa_web_server" vendor="ncsa">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0071" seq="1999-0071" published="1997-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0072" seq="1999-0072" published="1997-10-22" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX xdat gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0073" seq="1999-0073" published="1995-10-13" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="osf_1" vendor="digital">
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.2"/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num="3.2g"/>
        <vers num="4.0"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0074" seq="1999-0074" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Listening TCP ports are sequentially allocated, allowing spoofing attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0075" seq="1999-0075" published="1996-10-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0076" seq="1999-0076" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in wu-ftp from PASV command causes a core dump.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0077" seq="1999-0077" published="1995-01-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Predictable TCP sequence numbers allow spoofing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/139">tcp-seq-predict(139)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0078" seq="1999-0078" published="1996-04-18" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="1.9" CVSS_base_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="mp-ras" vendor="ncr">
        <vers num="2.03"/>
        <vers num="3.0"/>
        <vers num="3.01"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num=""/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="up-ux_v" vendor="nec">
        <vers num=""/>
      </prod>
      <prod name="nextstep" vendor="next">
        <vers num=""/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0079" seq="1999-0079" published="1997-09-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bisonware_ftp_server" vendor="bisonware">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0080" seq="1999-0080" published="1995-11-30" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0081" seq="1999-0081" published="1997-01-11" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">wu-ftp allows files to be overwritten via the rnfr command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0082" seq="1999-0082" published="1988-11-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">CWD ~root command in ftpd allows root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FARMERVENEMA" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp" vendor="ftp">
        <vers num=""/>
      </prod>
      <prod name="ftpcd" vendor="ftpcd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0083" seq="1999-0083" published="1997-06-11" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">getcwd() file descriptor leak in FTP.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0084" seq="1999-0084" published="1990-05-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/78">nfs-mknod(78)</ref>
    </refs>
    <vuln_soft>
      <prod name="nfs" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0085" seq="1999-0085" published="1996-08-21" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/118">rwhod-vuln(118)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/119">rwhod(119)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0086" seq="1999-0086" published="1998-01-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">AIX routed allows remote users to modify sensitive files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0087" seq="1999-0087" published="1998-02-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0088" seq="1999-0088" published="1998-10-26" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0089" seq="1999-0089" published="1997-10-28" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX libDtSvc library can allow local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0090" seq="1999-0090" published="1997-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX rcp command allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0091" seq="1999-0091" published="1997-10-28" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX writesrv command allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0092" seq="1999-0092" published="1997-10-29" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Various vulnerabilities in the AIX portmir command allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0093" seq="1999-0093" published="1997-10-29" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0094" seq="1999-0094" published="1997-10-29" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AIX piodmgrsu command allows local users to gain additional group privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0095" seq="1999-0095" published="1988-10-01" modified="2019-06-11" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2019/Jun/16">20190611 The Return of the WIZard: RCE in Exim (CVE-2019-10149)</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2019/06/05/4">[oss-security] 20190605 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2019/06/06/1">[oss-security] 20190606 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="5.58"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0096" seq="1999-0096" published="1996-12-10" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Sendmail decode alias can be used to overwrite sensitive files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num=""/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0097" seq="1999-0097" published="1997-10-29" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="9.01"/>
        <vers num="9.03"/>
        <vers num="9.04"/>
        <vers num="9.05"/>
        <vers num="9.06"/>
        <vers num="9.07"/>
        <vers num="9.08"/>
        <vers num="9.09"/>
        <vers num="9.10"/>
        <vers num="10.00"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3c"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0098" seq="1999-0098" published="1998-04-01" modified="2018-01-08" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="appleshare" vendor="apple">
        <vers num="-" edition="::ja"/>
      </prod>
      <prod name="mercury_mail_server" vendor="pmail">
        <vers num="-"/>
      </prod>
      <prod name="slmail" vendor="seattlelab">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0099" seq="1999-0099" published="1995-10-19" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
      <prod name="convexos" vendor="convex">
        <vers num="10.1"/>
        <vers num="10.2"/>
        <vers num="11.0"/>
        <vers num="11.1"/>
      </prod>
      <prod name="spp-ux" vendor="convex">
        <vers num="3"/>
      </prod>
      <prod name="unicos" vendor="cray">
        <vers num="8.0"/>
        <vers num="8.3"/>
        <vers num="9.0"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0100" seq="1999-0100" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Remote access in AIX innd 1.5.1, using control messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="1.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0101" seq="1999-0101" published="1996-12-10" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml" adv="1">H-13</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0102" seq="1999-0102" published="1998-07-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="slmail" vendor="seattle_lab_software">
        <vers num="3.0.2421"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0103" seq="1999-0103" published="1996-02-08" modified="2018-08-22" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="https://ics-cert.us-cert.gov/advisories/ICSMA-18-233-01">https://ics-cert.us-cert.gov/advisories/ICSMA-18-233-01</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0104" seq="1999-0104" published="1997-12-16" modified="2018-08-22" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/80175">80175</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5743">oval:org.mitre.oval:def:5743</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.0"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num="0a"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0105" seq="1999-0105" published="1997-03-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">finger allows recursive searches by using a long string of @ symbols.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0106" seq="1999-0106" published="1997-03-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Finger redirection allows finger bombs.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0107" seq="1999-0107" published="1997-12-30" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="0.8.11"/>
        <vers num="0.8.14"/>
        <vers num="1.0"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0108" seq="1999-0108" published="1998-05-01" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The printers program in IRIX has a buffer overflow that gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/1997/May/191">19970527 another day, another buffer overflow....</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0109" seq="1999-0109" published="1997-02-10" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ffbconfig in Solaris 2.5.1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0110" seq="1999-0110" published="1999-01-01" modified="2008-09-09" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0315.  Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315.  Notes: All CVE users should reference CVE-1999-0315 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0111" seq="1999-0111" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">RIP v1 is susceptible to spoofing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0112" seq="1999-0112" published="1997-05-01" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX dtterm program for the CDE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/878">dtterm-bo(878)</ref>
    </refs>
    <vuln_soft>
      <prod name="cde" vendor="cde">
        <vers num=""/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0113" seq="1999-0113" published="1994-05-23" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Some implementations of rlogin allow root access if given a -froot parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0114" seq="1999-0114" published="1998-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="elm" vendor="elm_development_group">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0115" seq="1999-0115" published="1997-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AIX bugfiler program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0116" seq="1999-0116" published="1996-09-19" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref>
    </refs>
    <vuln_soft>
      <prod name="sng" vendor="ibm">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0117" seq="1999-0117" published="1992-03-31" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AIX passwd allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0118" seq="1999-0118" published="1998-11-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AIX infod allows local users to gain root access through an X display.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0119" seq="1999-0119" published="1999-01-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT 4.0 beta allows users to read and delete shares.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0120" seq="1999-0120" published="1994-03-21" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0121" seq="1999-0121" published="1999-01-21" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in dtaction command gives root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0122" seq="1999-0122" published="1997-07-21" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX lchangelv gives root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0123" seq="1999-0123" published="1995-12-01" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Race condition in Linux mailx command allows local users to read user files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0124" seq="1999-0124" published="1993-08-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="gopherd" vendor="university_of_minnesota">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0125" seq="1999-0125" published="1998-01-25" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in SGI IRIX mailx program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.3"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0126" seq="1999-0126" published="1998-05-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SGI IRIX buffer overflow in xterm and Xaw allows root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref>
    </refs>
    <vuln_soft>
      <prod name="xfree86" vendor="xfree86_project">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0127" seq="1999-0127" published="1996-12-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0128" seq="1999-0128" published="1996-12-18" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sng" vendor="ibm">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="osf_1" vendor="digital">
        <vers num="1.3.3"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="1.3.0"/>
        <vers num="2.0"/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
      </prod>
      <prod name="tcp_ip" vendor="sco">
        <vers num="1.2.1"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4" edition=":x86"/>
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0129" seq="1999-0129" published="1996-12-03" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.8"/>
        <vers num="8.8.1"/>
        <vers num="8.8.2"/>
        <vers num="8.8.3"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0130" seq="1999-0130" published="1996-11-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Local users can start Sendmail in daemon mode and gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref>
    </refs>
    <vuln_soft>
      <prod name="network_desktop" vendor="caldera">
        <vers num="1.0"/>
      </prod>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.7"/>
        <vers num="8.8"/>
        <vers num="8.8.1"/>
        <vers num="8.8.2"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0131" seq="1999-0131" published="1996-09-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.6"/>
        <vers num="8.7.1"/>
        <vers num="8.7.2"/>
        <vers num="8.7.3"/>
        <vers num="8.7.4"/>
        <vers num="8.7.5"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="osf_1" vendor="digital">
        <vers num="1.3.2"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.5"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="3.0.3"/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num="1.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0132" seq="1999-0132" published="1996-08-15" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/401">expreserve(401)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
        <vers num="4.1.3u1"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0133" seq="1999-0133" published="1996-08-14" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="framemaker" vendor="adobe">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0134" seq="1999-0134" published="1996-08-06" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">vold in Solaris 2.x allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.4" edition=":x86"/>
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0135" seq="1999-0135" published="1996-07-25" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">admintool in Solaris allows a local user to write to arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0136" seq="1999-0136" published="1996-07-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0137" seq="1999-0137" published="1996-07-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="dip" vendor="fred_n._van_kempen">
        <vers num="3.3.7o"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0138" seq="1999-0138" published="1996-06-26" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="a_ux" vendor="apple">
        <vers num="3.1.1"/>
      </prod>
      <prod name="osf_1" vendor="digital">
        <vers num="1.3"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="8"/>
        <vers num="9"/>
        <vers num="10"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.5"/>
        <vers num="4"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="1.2.0"/>
        <vers num="2.0"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num=""/>
      </prod>
      <prod name="ews-ux_v" vendor="nec">
        <vers num="4.2"/>
        <vers num="4.2mp"/>
      </prod>
      <prod name="up-ux_v" vendor="nec">
        <vers num="4.2mp"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0139" seq="1999-0139" published="1998-12-12" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0140" seq="1999-0140" published="1999-06-30" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in RAS/PPTP on NT systems.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0141" seq="1999-0141" published="1996-03-29" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref>
    </refs>
    <vuln_soft>
      <prod name="navigator" vendor="netscape">
        <vers num="2.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0142" seq="1999-0142" published="1996-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="navigator" vendor="netscape">
        <vers num=""/>
      </prod>
      <prod name="java" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0143" seq="1999-0143" published="1996-02-21" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0"/>
        <vers num="5"/>
      </prod>
      <prod name="multinet" vendor="process_software">
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0144" seq="1999-0144" published="1997-06-01" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://cr.yp.to/qmail/venema.html" adv="1">http://cr.yp.to/qmail/venema.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602558319024&amp;w=2" adv="1">19970612 qmail-dos-2.c, another denial of service attack</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602558319029&amp;w=2" adv="1">19970612 Re: Denial of service (qmail-smtpd)</ref>
      <ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2237" adv="1">2237</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/208">qmail-rcpt(208)</ref>
    </refs>
    <vuln_soft>
      <prod name="qmail" vendor="qmail">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0145" seq="1999-0145" published="1993-09-30" modified="2019-06-11" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Sendmail WIZ command enabled, allowing root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://seclists.org/fulldisclosure/2019/Jun/16">20190611 The Return of the WIZard: RCE in Exim (CVE-2019-10149)</ref>
      <ref source="FARMERVENEMA" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2019/06/05/4">[oss-security] 20190605 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2019/06/06/1">[oss-security] 20190606 Re: CVE-2019-10149: Exim 4.87 to 4.91: possible remote exploit</ref>
      <ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0146" seq="1999-0146" published="1997-07-15" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/298">http-cgi-campas(298)</ref>
    </refs>
    <vuln_soft>
      <prod name="campas" vendor="ncsa">
        <vers num=""/>
      </prod>
      <prod name="servers" vendor="ncsa">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0147" seq="1999-0147" published="1997-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="glimpse_http" vendor="university_of_arizona">
        <vers num="2.0"/>
      </prod>
      <prod name="webglimpse" vendor="university_of_arizona">
        <vers num="1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0148" seq="1999-0148" published="1997-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The handler CGI program in IRIX allows arbitrary command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0149" seq="1999-0149" published="1997-04-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/290">http-sgi-wrap(290)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0150" seq="1999-0150" published="1997-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Perl fingerd program allows arbitrary command execution from remote users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="fingerd" vendor="gnu">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0151" seq="1999-0151" published="1995-04-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="satan" vendor="satan">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0152" seq="1999-0152" published="1997-08-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The DG/UX finger daemon allows remote command execution through shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="dg_ux" vendor="data_general">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0153" seq="1999-0153" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0154" seq="1999-0154" published="1999-12-31" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0155" seq="1999-0155" published="1995-08-31" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ghostscript" vendor="aladdin_enterprises">
        <vers num="2.6"/>
        <vers num="3.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0156" seq="1999-0156" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">wu-ftpd FTP daemon allows any user and password combination.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0157" seq="1999-0157" published="1998-08-18" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.2p"/>
        <vers num="11.3t"/>
        <vers num="12.0"/>
        <vers num="12.0t"/>
      </prod>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="4.2(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0158" seq="1999-0158" published="1998-08-31" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml" adv="1" patch="1">20010913 Cisco PIX Firewall Manager File Exposure</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="4.1(6)"/>
        <vers num="4.2(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0159" seq="1999-0159" published="1998-08-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="9.1"/>
        <vers num="11.0(20.3)"/>
        <vers num="11.1(15)ca"/>
        <vers num="11.1(16)"/>
        <vers num="11.1(16)aa"/>
        <vers num="11.1(16)ia"/>
        <vers num="11.1(17)cc"/>
        <vers num="11.1(17)ct"/>
        <vers num="11.2(8)sa3"/>
        <vers num="11.2(9)p"/>
        <vers num="11.2(9)xa"/>
        <vers num="11.2(10)"/>
        <vers num="11.2(10)bc"/>
        <vers num="11.3(1)"/>
        <vers num="11.3(1)ed"/>
        <vers num="11.3(1)t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0160" seq="1999-0160" published="1997-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="4.1"/>
        <vers num="9.1"/>
        <vers num="10.3"/>
        <vers num="11.0"/>
        <vers num="11.1"/>
        <vers num="11.2"/>
        <vers num="11.2p"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0161" seq="1999-0161" published="1995-07-31" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="10.3(3.4)"/>
        <vers num="10.3(4.2)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0162" seq="1999-0162" published="1998-09-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0163" seq="1999-0163" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0164" seq="1999-0164" published="1995-08-29" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A race condition in the Solaris ps command allows an attacker to overwrite critical files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0165" seq="1999-0165" published="1997-03-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NFS cache poisoning.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="nfs" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num=""/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0166" seq="1999-0166" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">NFS allows users to use a "cd .." command to access other directories besides the exported file system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="nfs" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0167" seq="1999-0167" published="1991-12-06" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0168" seq="1999-0168" published="1992-06-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0169" seq="1999-0169" published="1997-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NFS allows attackers to read and write any file on the system by specifying a false UID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="nfs" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0170" seq="1999-0170" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ultrix" vendor="digital">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0171" seq="1999-0171" published="1997-01-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in syslog by sending it a large number of superfluous messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0172" seq="1999-0172" published="1995-08-02" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FormMail CGI program allows remote execution of commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="formmail" vendor="matt_wright">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0173" seq="1999-0173" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FormMail CGI program can be used by web servers other than the host server that the program resides on.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="formmail" vendor="matt_wright">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0174" seq="1999-0174" published="1997-02-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
        <vers num="4.05"/>
        <vers num="4.06"/>
        <vers num="4.07"/>
        <vers num="4.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0175" seq="1999-0175" published="1996-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="web_server" vendor="novell">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0176" seq="1999-0176" published="1997-07-10" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Webgais program allows a remote user to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="webgais" vendor="webgais_development_team">
        <vers num="1.0b2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0177" seq="1999-0177" published="1997-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="website" vendor="oreilly">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0178" seq="1999-0178" published="1997-01-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/295">http-website-winsample(295)</ref>
    </refs>
    <vuln_soft>
      <prod name="oreilly_website" vendor="oreilly">
        <vers num="1.1e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0179" seq="1999-0179" published="1997-01-01" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q140818">Q140818</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0180" seq="1999-0180" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">in.rshd allows users to login with a NULL username and execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0181" seq="1999-0181" published="1994-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="rpc.walld" vendor="rpc.walld">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0182" seq="1999-0182" published="1997-09-30" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="1.9.17" prev="1" edition="p2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0183" seq="1999-0183" published="1997-09-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Linux implementations of TFTP would allow access to files outside the restricted directory.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="tftp" vendor="tftp">
        <vers num=""/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0184" seq="1999-0184" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="9.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0185" seq="1999-0185" published="1997-10-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0186" seq="1999-0186" published="1998-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0187" seq="1999-0187" published="1999-01-01" modified="2008-09-09" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0022.  Reason: This candidate is a duplicate of CVE-1999-0022.  Notes: All CVE users should reference CVE-1999-0022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0188" seq="1999-0188" published="1998-12-17" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The passwd command in Solaris can be subjected to a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0189" seq="1999-0189" published="1997-06-04" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0190" seq="1999-0190" published="1998-04-08" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0191" seq="1999-0191" published="1997-09-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">IIS newdsn.exe CGI script allows remote users to overwrite files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0192" seq="1999-0192" published="1997-10-18" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0" edition=":i386"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0193" seq="1999-0193" published="1997-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cascadeview_ux" vendor="ascend">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0194" seq="1999-0194" published="1999-05-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in in.comsat allows attackers to generate messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0195" seq="1999-0195" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0196" seq="1999-0196" published="1997-07-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref>
    </refs>
    <vuln_soft>
      <prod name="webgais" vendor="webgais_development_team">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0197" seq="1999-0197" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">finger 0@host on some systems may print information on some user accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0198" seq="1999-0198" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">finger .@host on some systems may print information on some user accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0200" seq="1999-0200" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0201" seq="1999-0201" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ftp" vendor="ftp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0202" seq="1999-0202" published="1997-01-01" modified="2010-03-26" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="university_of_washington">
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0203" seq="1999-0203" published="1995-08-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.6.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0204" seq="1999-0204" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0205" seq="1999-0205" published="1999-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Sendmail 8.6.11 and 8.6.12.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.6.11"/>
        <vers num="8.6.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0206" seq="1999-0206" published="1996-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.8"/>
        <vers num="8.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0207" seq="1999-0207" published="1994-06-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="majordomo" vendor="great_circle_associates">
        <vers num="1.90"/>
        <vers num="1.91"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0208" seq="1999-0208" published="1995-12-12" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
      </prod>
      <prod name="asl_ux_4800" vendor="nec">
        <vers num=""/>
      </prod>
      <prod name="ews-ux_v" vendor="nec">
        <vers num=""/>
      </prod>
      <prod name="up-ux_v" vendor="nec">
        <vers num=""/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="3"/>
        <vers num="4"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0209" seq="1999-0209" published="1990-08-14" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The SunView (SunTools) selection_svc facility allows remote users to read files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0210" seq="1999-0210" published="1997-11-26" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html" adv="1" patch="1">CA-99-05</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0211" seq="1999-0211" published="1994-02-14" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0212" seq="1999-0212" published="1998-04-29" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml" patch="1">I-048</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0213" seq="1999-0213" published="1998-07-15" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0214" seq="1999-0214" published="1992-07-21" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of service by sending forged ICMP unreachable packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0215" seq="1999-0215" published="1998-10-26" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Routed allows attackers to append data to files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="3"/>
        <vers num="4"/>
        <vers num="5"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0216" seq="1999-0216" published="1997-11-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service of inetd on Linux through SYN and RST packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inet" vendor="gnu">
        <vers num="5.01"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0217" seq="1999-0217" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.0.3"/>
        <vers num="4.0.3c"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3a1"/>
        <vers num="4.1psr_a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0218" seq="1999-0218" published="1995-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Livingston portmaster machines could be rebooted via a series of commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="portmaster" vendor="livingston_portmaster">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0219" seq="1999-0219" published="1997-07-01" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/205">ftp-servu(205)</ref>
    </refs>
    <vuln_soft>
      <prod name="serv-u" vendor="cat_soft">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0220" seq="1999-0220" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Attackers can do a denial of service of IRC by crashing the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0221" seq="1999-0221" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service of Ascend routers through port 150 (remote administration).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ascend_routers" vendor="lucent">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0222" seq="1999-0222" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0223" seq="1999-0223" published="1999-03-01" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0224" seq="1999-0224" published="1999-07-23" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Denial of service in Windows NT messenger service through a long username.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0225" seq="1999-0225" published="1998-02-14" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref>
      <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp" adv="1" patch="1">19980214 Windows NT Logon Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0226" seq="1999-0226" published="1999-01-01" modified="2017-05-03" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0227" seq="1999-0227" published="1997-06-01" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154087">Q154087</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0228" seq="1999-0228" published="1997-02-07" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q162567">Q162567</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0229" seq="1999-0229" published="1999-05-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Windows NT IIS server using ..\..</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0230" seq="1999-0230" published="1997-12-15" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Cisco 7xx routers through the telnet service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0231" seq="1999-0231" published="1999-01-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="slmail" vendor="seattle_lab_software">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0232" seq="1999-0232" published="1995-02-01" modified="2017-05-03" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ncsa_httpd" vendor="ncsa_httpd_project">
        <vers num="1.5c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0233" seq="1999-0233" published="1996-02-25" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q148188">Q148188</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q155056">Q155056</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0234" seq="1999-0234" published="1996-10-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bash treats any character with a value of 255 as a command separator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="3.0.3"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="4.2"/>
      </prod>
      <prod name="linux" vendor="yggdrasil">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0235" seq="1999-0235" published="1995-02-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ncsa_web_server" vendor="ncsa">
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0236" seq="1999-0236" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
      <prod name="servers" vendor="ncsa">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0237" seq="1999-0237" published="1997-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Remote execution of arbitrary commands through Guestbook CGI program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cgi_guestbook" vendor="webcom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0238" seq="1999-0238" published="1997-08-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">php.cgi allows attackers to read any file on the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="2.0b10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0239" seq="1999-0239" published="1998-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0240" seq="1999-0240" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0241" seq="1999-0241" published="1995-11-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num=""/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0242" seq="1999-0242" published="1995-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0243" seq="1999-0243" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux cfingerd could be exploited to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0244" seq="1999-0244" published="1997-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="radius" vendor="livingston">
        <vers num="1.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0245" seq="1999-0245" published="1995-09-07" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0246" seq="1999-0246" published="1996-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP Remote Watch allows a remote user to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0247" seq="1999-0247" published="1997-07-21" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1443" adv="1">1443</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="1.4"/>
        <vers num="1.4sec"/>
        <vers num="1.4sec2"/>
        <vers num="1.4unoff3"/>
        <vers num="1.4unoff4"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0248" seq="1999-0248" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref>
      <ref source="CONFIRM" url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0249" seq="1999-0249" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT RSHSVC program allows remote users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0250" seq="1999-0250" published="1997-07-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of service in Qmail through long SMTP commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref>
      <ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
    </refs>
    <vuln_soft>
      <prod name="qmail" vendor="dan_bernstein">
        <vers num="1.01" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0251" seq="1999-0251" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in talk program allows remote attackers to disrupt a user's display.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="talkd" vendor="talkd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0252" seq="1999-0252" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in listserv allows arbitrary command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="listserv" vendor="lsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0253" seq="1999-0253" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0254" seq="1999-0254" published="1998-11-02" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0255" seq="1999-0255" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ircd allows arbitrary command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0256" seq="1999-0256" published="1998-02-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in War FTP allows remote execution of commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="warftpd" vendor="jgaa">
        <vers num="1.66" prev="1"/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0257" seq="1999-0257" published="1998-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Nestea variation of teardrop IP fragmentation denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0258" seq="1999-0258" published="1998-02-13" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Bonk variation of teardrop IP fragmentation denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0259" seq="1999-0259" published="1997-05-23" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">cfingerd lists all users on a system via search.**@target.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cfingerd" vendor="infodrom">
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0260" seq="1999-0260" published="1996-12-24" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The jj CGI program allows command execution via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="jj" vendor="renaud_deraison">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0261" seq="1999-0261" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.insecure.org/sploits/netmanage.chameleon.overflows.html">http://www.insecure.org/sploits/netmanage.chameleon.overflows.html</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0262" seq="1999-0262" published="1998-08-04" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2056">2056</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1532">http-cgi-faxsurvey(1532)</ref>
    </refs>
    <vuln_soft>
      <prod name="faxsurvey" vendor="renaud_deraison">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0263" seq="1999-0263" published="1998-07-16" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Solaris SUNWadmap can be exploited to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173">00173</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0264" seq="1999-0264" published="1998-01-27" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">htmlscript CGI program allows remote read access to files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="htmlscript" vendor="miva">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0265" seq="1999-0265" published="1997-01-01" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ICMP redirect messages may crash or lock up a host.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154174">Q154174</ref>
    </refs>
    <vuln_soft>
      <prod name="os-9" vendor="microware">
        <vers num=""/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="3.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0266" seq="1999-0266" published="1998-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The info2www CGI script allows remote file access or remote command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1995">1995</ref>
    </refs>
    <vuln_soft>
      <prod name="info2www" vendor="roar_smith">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0267" seq="1999-0267" published="1997-09-23" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ncsa_httpd" vendor="ncsa">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0268" seq="1999-0268" published="1999-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="metaweb" vendor="metainfo">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0269" seq="1999-0269" published="1998-08-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Enterprise servers may list files through the PageServices query.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0270" seq="1999-0270" published="1998-04-03" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P">19980401-01-P</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-041.shtml">I-041</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/64">64</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/810">sgi-pfdispaly(810)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0271" seq="1999-0271" published="1998-01-15" modified="2005-10-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Progressive Networks Real Video server (pnserver) can be crashed remotely.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0272" seq="1999-0272" published="1997-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Slmail v2.5 through the POP3 port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="slmail" vendor="slmail">
        <vers num="3.0.2421"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0273" seq="1999-0273" published="1998-01-01" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0274" seq="1999-0274" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0275" seq="1999-0275" published="1997-06-10" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0276" seq="1999-0276" published="1999-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mSQL v2.0.1 and below allows remote execution through a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="msql" vendor="hughes">
        <vers num="2.0."/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0277" seq="1999-0277" published="1996-10-28" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The WorkMan program can be used to overwrite any file to get root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0278" seq="1999-0278" published="1998-06-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-003">MS98-003</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A913">oval:org.mitre.oval:def:913</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0279" seq="1999-0279" published="1998-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ews" vendor="excite">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0280" seq="1999-0280" published="1997-04-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0281" seq="1999-0281" published="1997-06-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in IIS using long URLs.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0282" seq="1999-0282" published="1997-09-23" modified="2008-09-09" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1584, CVE-1999-1586.  Reason: This candidate combined references from one issue with the description from another issue.  Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0283" seq="1999-0283" published="1999-01-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Java Web Server would allow remote users to obtain the source code for CGI programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88256790401004&amp;w=2">19970716 Viewable .jhtml source with JavaWebServer</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0284" seq="1999-0284" published="1998-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="lotus_domino_mail_server" vendor="ibm">
        <vers num=""/>
      </prod>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0285" seq="1999-0285" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0286" seq="1999-0286" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0287" seq="1999-0287" published="1999-04-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the Wguest CGI program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cgi_guestbook" vendor="webcom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0288" seq="1999-0288" published="1998-08-01" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://safenetworks.com/Windows/wins.html">http://safenetworks.com/Windows/wins.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1233">nt-winsupd-fix(1233)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0289" seq="1999-0289" published="1999-12-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0290" seq="1999-0290" published="1998-02-21" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wingate" vendor="qbik">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0291" seq="1999-0291" published="1999-02-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wingate" vendor="qbik">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0292" seq="1999-0292" published="1997-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service through Winpopup using large user names.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0293" seq="1999-0293" published="1998-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AAA authentication on Cisco systems allows attackers to execute commands without authorization.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0294" seq="1999-0294" published="1997-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">All records in a WINS database can be deleted through SNMP for a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wins" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0295" seq="1999-0295" published="1997-10-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0296" seq="1999-0296" published="1998-02-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris volrmmount program allows attackers to read any file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162">00162</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0297" seq="1999-0297" published="1996-12-12" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="vixie_cron" vendor="paul_vixie">
        <vers num="3.0"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.0"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0298" seq="1999-0298" published="1997-02-05" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp">19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0299" seq="1999-0299" published="1997-03-05" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD lpd through long DNS hostnames.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0300" seq="1999-0300" published="1997-10-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0301" seq="1999-0301" published="1997-08-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SunOS/Solaris ps command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0302" seq="1999-0302" published="1998-09-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176">00176</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0303" seq="1999-0303" published="1998-05-21" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="osf_1" vendor="digital">
        <vers num="1.1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="" edition=":x86"/>
        <vers num="1.1.3" edition="u1"/>
        <vers num="1.1.4" edition=":jl"/>
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0304" seq="1999-0304" published="1998-02-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.0"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0305" seq="1999-0305" published="1998-02-01" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.openbsd.org/advisories/sourceroute.txt">http://www.openbsd.org/advisories/sourceroute.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/736">bsd-sourceroute(736)</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num=""/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2"/>
        <vers num="2.2.5"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0306" seq="1999-0306" published="1997-11-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">buffer overflow in HP xlock program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="vvos" vendor="hp">
        <vers num="10.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0307" seq="1999-0307" published="2000-12-20" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in HP-UX cstm program allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="10.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0308" seq="1999-0308" published="1996-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP-UX gwind program allows users to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0309" seq="1999-0309" published="1997-02-01" modified="2013-07-21" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP-UX vgdisplay program gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0310" seq="1999-0310" published="1998-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH 1.2.25 on HP-UX allows access to new user accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0311" seq="1999-0311" published="1996-11-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">fpkg2swpk in HP-UX allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0312" seq="1999-0312" published="1993-01-13" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">HP ypbind allows attackers with root privileges to modify NIS data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0313" seq="1999-0313" published="1998-07-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
      <ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/214">214</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1441">sgi-disk-bandwidth(1441)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.4" edition=":s2mp"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0314" seq="1999-0314" published="1998-07-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/213">213</ref>
      <ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1199">sgi-ioconfig(1199)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0315" seq="1999-0315" published="1997-04-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris fdformat command gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0316" seq="1999-0316" published="1995-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Linux splitvt command gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="splitvt" vendor="sam_lantinga">
        <vers num="1.6.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0317" seq="1999-0317" published="1999-11-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Linux su command gives root access to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0318" seq="1999-0318" published="1997-03-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0319" seq="1999-0319" published="1996-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0320" seq="1999-0320" published="1998-03-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0321" seq="1999-0321" published="1998-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0322" seq="1999-0322" published="1997-10-29" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The open() function in FreeBSD allows local attackers to write to arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.0"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0323" seq="1999-0323" published="1998-02-20" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">FreeBSD mmap function allows users to modify append-only or immutable files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc">1998-003</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.0"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0324" seq="1999-0324" published="1996-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ppl program in HP-UX allows local users to create root files through symlinks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0325" seq="1999-0325" published="1995-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="8"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0326" seq="1999-0326" published="1997-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in HP-UX mediainit program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0327" seq="1999-0327" published="1997-11-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SGI syserr program allows local users to corrupt files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0328" seq="1999-0328" published="1997-11-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SGI permissions program allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0329" seq="1999-0329" published="1998-06-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SGI mediad program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX">19980602-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0330" seq="1999-0330" published="1998-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux bdash game has a buffer overflow that allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0331" seq="1999-0331" published="1998-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 4.0(1).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0332" seq="1999-0332" published="1998-12-01" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in NetMeeting allows denial of service and remote command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q184346">Q184346</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0333" seq="1999-0333" published="1998-08-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0334" seq="1999-0334" published="1993-12-16" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0335" seq="1999-0335" published="1996-08-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0336" seq="1999-0336" published="1996-11-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in mstm in HP-UX allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0337" seq="1999-0337" published="1994-06-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="2.2.1"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0338" seq="1999-0338" published="1994-02-24" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AIX Licensed Program Product performance tools allow local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0339" seq="1999-0339" published="1998-08-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0340" seq="1999-0340" published="1997-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Linux Slackware crond program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0341" seq="1999-0341" published="1998-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="1.3.1"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0342" seq="1999-0342" published="1998-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux PAM modules allow local users to gain root access using temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="pam" vendor="pam">
        <vers num="0.64" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0343" seq="1999-0343" published="1998-10-02" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A malicious Palace server can force a client to execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="palace_client" vendor="palace">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0344" seq="1999-0344" published="1998-08-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NT users can gain debug-level access on a system process using the Sechole exploit.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q190288">Q190288</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-009">MS98-009</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0345" seq="1999-0345" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sng" vendor="ibm">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.5.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0346" seq="1999-0346" published="1997-10-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CGI PHP mlog script allows an attacker to read any file on the target server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
    </refs>
    <vuln_soft>
      <prod name="php_fi" vendor="php">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0347" seq="1999-0347" published="1999-01-26" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91745430007021&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91756771207719&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0348" seq="1999-0348" published="1999-01-27" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q197003">Q197003</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0349" seq="1999-0349" published="1999-01-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q188348">Q188348</ref>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/IIS%20Remote%20FTP%20Exploit/DoS%20Attack.html">IIS Remote FTP Exploit/DoS Attack</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-003">MS99-003</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0350" seq="1999-0350" published="1999-02-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="clearcase" vendor="rational_software">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0351" seq="1999-0351" published="1999-02-01" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">FTP PASV "Pizza Thief" denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt">http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3389">pasv-pizza-thief-dos(3389)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_pasv" vendor="ftp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0352" seq="1999-0352" published="1999-01-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0353" seq="1999-0353" published="1999-02-10" modified="2013-09-03" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-026.shtml">J-026</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091">HPSBUX9902-091</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0354" seq="1999-0354" published="1999-11-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content.  Also applies to Outlook when the client views a malicious email message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-002">MS99-002</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="97"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0355" seq="1999-0355" published="1999-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="controlit" vendor="ca">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0356" seq="1999-0356" published="1999-01-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0357" seq="1999-0357" published="1999-01-25" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0358" seq="1999-0358" published="1999-02-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-027.shtml">J-027</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="4.0"/>
        <vers num="4.0a"/>
        <vers num="4.0b"/>
        <vers num="4.0c"/>
        <vers num="4.0d"/>
        <vers num="4.0e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0359" seq="1999-0359" published="2001-03-12" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ptylogin" vendor="marc_schaefer">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0360" seq="1999-0360" published="1999-01-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91763097004101&amp;w=2">19990130 Security Advisory for Internet Information Server 4 with Site</ref>
    </refs>
    <vuln_soft>
      <prod name="site_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0361" seq="1999-0361" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0362" seq="1999-0362" published="1999-02-02" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WS_FTP server remote denial of service through cwd command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02021999.html">AD02021999</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/217">217</ref>
    </refs>
    <vuln_soft>
      <prod name="ws_ftp_server" vendor="ipswitch">
        <vers num="1.0.1eval"/>
        <vers num="1.0.2eval"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0363" seq="1999-0363" published="1999-02-02" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/328">328</ref>
    </refs>
    <vuln_soft>
      <prod name="line_printer_control" vendor="plp">
        <vers num=""/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0364" seq="1999-0364" published="1999-01-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91816470220259&amp;w=2">19990204 Microsoft Access 97 Stores Database Password as Plaintext</ref>
    </refs>
    <vuln_soft>
      <prod name="total_vb_sourcebook" vendor="fms_inc.">
        <vers num="6.0"/>
      </prod>
      <prod name="access" vendor="microsoft">
        <vers num="97"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0365" seq="1999-0365" published="1999-02-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="metaip" vendor="metainfo">
        <vers num="3.1"/>
      </prod>
      <prod name="sendmail" vendor="metainfo">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0366" seq="1999-0366" published="1999-02-08" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q214840">Q214840</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-004">MS99-004</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0367" seq="1999-0367" published="1999-02-09" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">NetBSD netstat command allows local users to access kernel memory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0368" seq="1999-0368" published="1999-02-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2_pre1"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4.2_beta18"/>
        <vers num="2.4.2_beta18_vr9"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.3"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0369" seq="1999-0369" published="1997-02-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="" edition=":x86"/>
        <vers num="1.1.3" edition="u1"/>
        <vers num="1.1.4" edition=":jl"/>
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0370" seq="1999-0370" published="1999-02-10" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/165">165</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0371" seq="1999-0371" published="1999-02-11" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="lynx" vendor="university_of_kansas">
        <vers num="2.7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0372" seq="1999-0372" published="1999-02-12" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q217004">Q217004</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-005">MS99-005</ref>
    </refs>
    <vuln_soft>
      <prod name="backoffice" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0373" seq="1999-0373" published="1999-02-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0374" seq="1999-0374" published="1999-02-16" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Debian GNU/Linux cfengine package is susceptible to a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0375" seq="1999-0375" published="1999-02-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="network_flight_recorder" vendor="network_flight_recorder">
        <vers num="2.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0376" seq="1999-0376" published="1999-02-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-006">MS99-006</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0377" seq="1999-0377" published="1999-02-22" modified="2016-12-27" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1033881">1033881</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="unix">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0378" seq="1999-0378" published="1999-02-22" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0379" seq="1999-0379" published="1999-02-22" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/498">498</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-007">MS99-007</ref>
    </refs>
    <vuln_soft>
      <prod name="backoffice_resource_kit" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0380" seq="1999-0380" published="1999-02-25" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91996412724720&amp;w=2">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91999015212415&amp;w=2">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92110501504997&amp;w=2">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/497">497</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5392">slmail-ras-ntfs-bypass(5392)</ref>
    </refs>
    <vuln_soft>
      <prod name="slmail" vendor="seattle_lab_software">
        <vers num="3.0.2421"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0381" seq="1999-0381" published="1999-02-26" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/342" adv="1">342</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.990225011801.12757A-100000@eleet">19990225 SUPER buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0382" seq="1999-0382" published="1999-03-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-008">MS99-008</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1" edition="sp1"/>
        <vers num="3.5.1" edition="sp2"/>
        <vers num="3.5.1" edition="sp3"/>
        <vers num="3.5.1" edition="sp4"/>
        <vers num="3.5.1" edition="sp5"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0383" seq="1999-0383" published="1999-02-02" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ACC Tigris allows public access without a login.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/183">183</ref>
    </refs>
    <vuln_soft>
      <prod name="tigris" vendor="acc">
        <vers num="10.5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0384" seq="1999-0384" published="1999-01-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-001">MS99-001</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="98" edition=":mac"/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num="98"/>
      </prod>
      <prod name="project" vendor="microsoft">
        <vers num="98"/>
      </prod>
      <prod name="visual_basic" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0385" seq="1999-0385" published="1998-12-01" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-009">MS99-009</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0386" seq="1999-0386" published="1999-03-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-010">MS99-010</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="personal_web_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0387" seq="1999-0387" published="1999-11-29" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q168115">Q168115</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/829">829</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-052">MS99-052</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0388" seq="1999-0388" published="1999-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="suguard" vendor="datalynx">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0389" seq="1999-0389" published="1999-01-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the bootp server in the Debian Linux netstd package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/324" adv="1">324</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0390" seq="1999-0390" published="1999-01-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Dosemu Slang library in Linux.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt">CSSA-1999-006.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/187">187</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0391" seq="1999-0391" published="1999-01-05" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1" edition="sp1"/>
        <vers num="3.5.1" edition="sp2"/>
        <vers num="3.5.1" edition="sp3"/>
        <vers num="3.5.1" edition="sp4"/>
        <vers num="3.5.1" edition="sp5"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0392" seq="1999-0392" published="1999-01-10" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Thomas Boutell's cgic library version up to 1.05.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cgic_library" vendor="thomas_boutell">
        <vers num="1.05" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0393" seq="1999-0393" published="1999-01-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91694391227372&amp;w=2">19990121 Sendmail 8.8.x/8.9.x bugware</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.8"/>
        <vers num="8.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0394" seq="1999-0394" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0395" seq="1999-0395" published="1999-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise17.php" adv="1">19990118 Vulnerability in the BackWeb Polite Agent Protocol</ref>
    </refs>
    <vuln_soft>
      <prod name="backweb_polite_agent_protocol" vendor="backweb_technologies">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0396" seq="1999-0396" published="1999-02-17" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0397" seq="1999-0397" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0398" seq="1999-0398" published="1999-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.27"/>
      </prod>
      <prod name="ssh2" vendor="ssh">
        <vers num="2.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0399" seq="1999-0399" published="1999-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="mirc" vendor="khaled_mardam-bey">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0400" seq="1999-0400" published="1999-01-26" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Denial of service in Linux 2.2.0 running the ldd command on a core file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/344" adv="1">344</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0401" seq="1999-0401" published="1999-01-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0402" seq="1999-0402" published="1999-01-02" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wget" vendor="gnu">
        <vers num="1.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0403" seq="1999-0403" published="1999-02-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91821080015725&amp;w=2">19990204 Cyrix bug: freeze in hell, badboy</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="cyrix">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0404" seq="1999-0404" published="1999-02-14" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="mailmax" vendor="smartmax_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0405" seq="1999-0405" published="1999-02-18" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A buffer overflow in lsof allows local users to obtain root privilege.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2" edition=":i386"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0406" seq="1999-0406" published="1999-02-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0407" seq="1999-0407" published="1999-02-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91983486431506&amp;w=2">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92000623021036&amp;w=2">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0408" seq="1999-0408" published="1999-02-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/337">337</ref>
    </refs>
    <vuln_soft>
      <prod name="cobalt_raq" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0409" seq="1999-0409" published="1999-03-04" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/319">319</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="3.5"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0410" seq="1999-0410" published="1999-03-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/293">293</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0411" seq="1999-0411" published="1999-03-07" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="3.0"/>
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0412" seq="1999-0412" published="1999-02-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/501">501</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0413" seq="1999-0413" published="1999-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX">19990301-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0414" seq="1999-0414" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0.30"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0415" seq="1999-0415" published="1999-03-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="cisco_7xx_routers" vendor="cisco">
        <vers num="3.2"/>
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0416" seq="1999-0416" published="1999-03-11" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="cisco_7xx_routers" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0417" seq="1999-0417" published="1999-03-09" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">64 bit Solaris 7 procfs allows local users to perform a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/448">448</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0418" seq="1999-0418" published="1999-03-08" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92100018214316&amp;w=2">19990308 SMTP server account probing</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0419" seq="1999-0419" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0420" seq="1999-0420" published="1999-03-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="umapfs" vendor="netbsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0421" seq="1999-0421" published="1999-03-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/338" adv="1" patch="1">338</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0422" seq="1999-0422" published="1999-03-17" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" flag set.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0423" seq="1999-0423" published="1994-06-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0424" seq="1999-0424" published="1999-03-18" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0425" seq="1999-0425" published="1999-03-18" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0426" seq="1999-0426" published="1999-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0427" seq="1999-0427" published="2000-05-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
      <prod name="eudora_light" vendor="qualcomm">
        <vers num="3.0"/>
      </prod>
      <prod name="eudora_pro" vendor="qualcomm">
        <vers num="1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0428" seq="1999-0428" published="1999-03-22" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num=""/>
      </prod>
      <prod name="ssleay" vendor="ssleay">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0429" seq="1999-0429" published="1999-03-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92221437025743&amp;w=2">19990323</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92241547418689&amp;w=2">19990324 Re: LNotes encryption</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92246997917866&amp;w=2">19990326 Lotus Notes Encryption Bug</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92249282302994&amp;w=2">19990326 Re: Lotus Notes security advisory</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_notes" vendor="ibm">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0430" seq="1999-0430" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="catalyst_12xx_supervisor_software" vendor="cisco">
        <vers num="4.29"/>
      </prod>
      <prod name="catalyst_29xx_supervisor_software" vendor="cisco">
        <vers num="1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.501"/>
        <vers num="2.1.502"/>
      </prod>
      <prod name="catalyst_5xxx_supervisor_software" vendor="cisco">
        <vers num="1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.501"/>
        <vers num="2.1.502"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0431" seq="1999-0431" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.</descript>
    </desc>
    <sols>
      <sol source="nvd">This problem was fixed in Linux kernel 2.2.4 and later releases.</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.1.89"/>
        <vers num="2.2.0"/>
        <vers num="2.2.3" prev="1"/>
        <vers num="2.2.10"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.15_pre20"/>
        <vers num="2.2.16" edition="pre6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0432" seq="1999-0432" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ftp on HP-UX 11.00 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094">HPSBUX9903-094</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0433" seq="1999-0433" published="1999-03-21" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.3"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="4.0"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0434" seq="1999-0434" published="1999-03-30" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/359" adv="1" patch="1">359</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.2"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0" edition="r5"/>
        <vers num="2.1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3.3"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.1"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0435" seq="1999-0435" published="1999-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0436" seq="1999-0436" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095">HPSBUX9903-095</ref>
    </refs>
    <vuln_soft>
      <prod name="desms" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0437" seq="1999-0437" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="webramp" vendor="ramp_networks">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0438" seq="1999-0438" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="webramp_200i" vendor="ramp_networks">
        <vers num="1.0"/>
      </prod>
      <prod name="webramp_m3" vendor="ramp_networks">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0439" seq="1999-0439" published="1999-04-05" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="procmail" vendor="procmail">
        <vers num="3.12" prev="1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0440" seq="1999-0440" published="1999-03-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://java.sun.com/pr/1999/03/pr990329-01.html">http://java.sun.com/pr/1999/03/pr990329-01.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92333596624452&amp;w=2">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1939">1939</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.5"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num="4.0"/>
        <vers num="4.01"/>
        <vers num="4.02"/>
        <vers num="4.03"/>
        <vers num="4.04"/>
        <vers num="4.05"/>
        <vers num="4.06"/>
        <vers num="4.07"/>
        <vers num="4.08"/>
        <vers num="4.61"/>
      </prod>
      <prod name="java" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0441" seq="1999-0441" published="1999-02-22" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02221999.html">AD02221999</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/509">509</ref>
    </refs>
    <vuln_soft>
      <prod name="wingate" vendor="qbik">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0442" seq="1999-0442" published="1999-01-07" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Solaris ff.core allows local users to modify files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/327">327</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0443" seq="1999-0443" published="1999-04-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
    </refs>
    <vuln_soft>
      <prod name="patrol_agent" vendor="bmc">
        <vers num="3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0444" seq="1999-0444" published="1999-04-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0445" seq="1999-0445" published="1999-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.0"/>
        <vers num="12.0(1)w"/>
        <vers num="12.0(1)xa3"/>
        <vers num="12.0(1)xb"/>
        <vers num="12.0(1)xe"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0(2)xf"/>
        <vers num="12.0(2)xg"/>
        <vers num="12.0db"/>
        <vers num="12.0s"/>
        <vers num="12.0t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0446" seq="1999-0446" published="1999-04-12" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0447" seq="1999-0447" published="1999-04-01" modified="2013-07-23" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Local users can gain privileges using the debug utility in the MPE/iX operating system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006">HPSBMP9904-006</ref>
    </refs>
    <vuln_soft>
      <prod name="mpe_ix" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0448" seq="1999-0448" published="1999-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0449" seq="1999-0449" published="1999-01-26" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/193">193</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0450" seq="1999-0450" published="1999-01-26" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/194">194</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0451" seq="1999-0451" published="1999-01-19" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/343" adv="1">343</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0"/>
        <vers num="2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0452" seq="1999-0452" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A service or application has a backdoor password that was placed there by the developer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0453" seq="1999-0453" published="1999-01-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).</descript>
      <descript source="nvd">Please see the following link for more information:

http://seclists.org/bugtraq/1999/Jan/0215.html</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0454" seq="1999-0454" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0455" seq="1999-0455" published="1999-12-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/115" adv="1">115</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0457" seq="1999-0457" published="1999-01-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux ftpwatch program allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/317">317</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0458" seq="1999-0458" published="1999-01-06" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="l0phtcrack" vendor="l0pht">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0459" seq="1999-0459" published="1999-02-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0460" seq="1999-0460" published="1999-02-19" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/312" adv="1">312</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0461" seq="1999-0461" published="1999-01-28" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0462" seq="1999-0462" published="1999-03-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/339" adv="1" patch="1">339</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0463" seq="1999-0463" published="1998-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can perform a denial of service using IRIX fcagent.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX">19981201-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod name="l0phtcrack" vendor="l0pht">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0464" seq="1999-0464" published="1999-01-04" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91553066310826&amp;w=2">19990104 Tripwire mess..</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=bugtraq&amp;m=91592136122066&amp;w=2">http://marc.info/?l=bugtraq&amp;m=91592136122066&amp;w=2</ref>
    </refs>
    <vuln_soft>
      <prod name="tripwire" vendor="tripwire">
        <vers num="1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0465" seq="1999-0465" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0466" seq="1999-0466" published="1999-04-21" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0467" seq="1999-0467" published="1999-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cgi_guestbook" vendor="webcom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0468" seq="1999-0468" published="1999-04-09" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012">MS99-012</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0469" seq="1999-0469" published="1999-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0470" seq="1999-0470" published="1999-04-09" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/482">482</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0471" seq="1999-0471" published="1999-04-09" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="winroute" vendor="winroute">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0472" seq="1999-0472" published="1999-04-07" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="snmp" vendor="snmp">
        <vers num=""/>
      </prod>
      <prod name="netcache" vendor="network_appliance">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0473" seq="1999-0473" published="1999-04-07" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/145">145</ref>
    </refs>
    <vuln_soft>
      <prod name="rsync" vendor="andrew_tridgell">
        <vers num="2.3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0474" seq="1999-0474" published="1999-04-05" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="99a_2.13build1700"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0475" seq="1999-0475" published="1999-04-05" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="procmail" vendor="procmail">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0476" seq="1999-0476" published="1999-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0477" seq="1999-0477" published="1999-12-25" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/115" adv="1" patch="1">115</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.01"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0478" seq="1999-0478" published="1998-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097">HPSBUX9904-097</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.9.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0479" seq="1999-0479" published="1999-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092">HPSBUX9903-092</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.6"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0480" seq="1999-0480" published="1999-04-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="midnight_commander" vendor="midnight_commander">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0481" seq="1999-0481" published="1999-03-22" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in "poll" in OpenBSD.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0482" seq="1999-0482" published="1999-03-21" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">OpenBSD kernel crash through TSS handling, as caused by the crashme program.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0483" seq="1999-0483" published="1999-02-25" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">OpenBSD crash using nlink value in FFS and EXT2FS filesystems.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0484" seq="1999-0484" published="1999-02-23" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in OpenBSD ping.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0485" seq="1999-0485" published="1999-02-19" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0486" seq="1999-0486" published="1998-02-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0487" seq="1999-0487" published="1999-05-01" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-011">MS99-011</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0488" seq="1999-0488" published="1999-04-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012">MS99-012</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1" edition="sp1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0489" seq="1999-0489" published="1999-05-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-015">MS99-015</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0490" seq="1999-0490" published="1999-04-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-012">MS99-012</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0491" seq="1999-0491" published="1999-04-20" modified="2014-12-31" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/119">119</ref>
    </refs>
    <vuln_soft>
      <prod name="bash" vendor="gnu">
        <vers num="1.14.0"/>
        <vers num="1.14.1"/>
        <vers num="1.14.2"/>
        <vers num="1.14.3"/>
        <vers num="1.14.4"/>
        <vers num="1.14.5"/>
        <vers num="1.14.6"/>
        <vers num="1.14.7"/>
        <vers num="2.0"/>
        <vers num="2.01"/>
        <vers num="2.01.1"/>
        <vers num="2.02"/>
        <vers num="2.02.1"/>
        <vers num="2.03"/>
        <vers num="2.04" prev="1"/>
        <vers num="2.05" edition="a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0492" seq="1999-0492" published="1999-04-23" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0493" seq="1999-0493" published="1999-06-07" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/186&amp;type=0&amp;nav=sec.sba">00186</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html" adv="1" patch="1">CA-99-05</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-045.shtml">J-045</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/450">450</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0494" seq="1999-0494" published="1998-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in WinGate proxy through a buffer overflow in POP3.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wingate" vendor="wingate">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0495" seq="1999-0495" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A remote attacker can gain access to a file system using ..  (dot dot) when accessing SMB shares.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0496" seq="1999-0496" published="1997-01-01" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q146965">Q146965</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0497" seq="1999-0497" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">Anonymous FTP is enabled.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">Anonymous FTP is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0498" seq="1999-0498" published="1991-09-27" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0499" seq="1999-0499" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NETBIOS share information may be published through SNMP registry keys in NT.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0501" seq="1999-0501" published="1998-06-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Unix account has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0502" seq="1999-0502" published="1998-03-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Unix account has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0503" seq="1999-0503" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT local user or administrator account has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0504" seq="1999-0504" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Windows NT local user or administrator account has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0505" seq="1999-0505" published="1998-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT domain user or administrator account has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0506" seq="1999-0506" published="1998-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT domain user or administrator account has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0507" seq="1999-0507" published="1998-04-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An account on a router, firewall, or other network device has a guessable password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0508" seq="1999-0508" published="1998-06-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An account on a router, firewall, or other network device has a default, null, blank, or missing password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0509" seq="1999-0509" published="1996-05-29" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0510" seq="1999-0510" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A router or firewall allows source routed packets from arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0511" seq="1999-0511" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IP forwarding is enabled on a machine which is not a router or firewall.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0512" seq="1999-0512" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0513" seq="1999-0513" published="1998-01-05" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="3.2g"/>
        <vers num="4.0"/>
        <vers num="4.0a"/>
        <vers num="4.0b"/>
        <vers num="4.0c"/>
        <vers num="4.0d"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.2"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0514" seq="1999-0514" published="1998-03-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0515" seq="1999-0515" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0516" seq="1999-0516" published="1998-08-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An SNMP community name is guessable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0517" seq="1999-0517" published="1997-01-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An SNMP community name is the default (e.g. public), null, or missing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
        <vers num="11.00"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0518" seq="1999-0518" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A NETBIOS/SMB share password is guessable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0519" seq="1999-0519" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A NETBIOS/SMB share password is the default, null, or missing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0520" seq="1999-0520" published="1999-01-01" modified="2005-10-20" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">A system-critical NETBIOS/SMB share has inappropriate access control.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0521" seq="1999-0521" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An NIS domain name is easily guessable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0522" seq="1999-0522" published="1996-05-28" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0523" seq="1999-0523" published="1999-01-01" modified="2010-12-01" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">ICMP echo (ping) is allowed from arbitrary hosts.</descript>
    </desc>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0524" seq="1999-0524" published="1997-08-01" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.</descript>
    </desc>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://descriptions.securescout.com/tc/11010">http://descriptions.securescout.com/tc/11010</ref>
      <ref source="MISC" url="http://descriptions.securescout.com/tc/11011">http://descriptions.securescout.com/tc/11011</ref>
      <ref source="CONFIRM" url="http://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10705">http://kb.juniper.net/InfoCenter/index?page=content&amp;id=JSA10705</ref>
      <ref source="MISC" url="http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434">http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/306">icmp-netmask(306)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/322">icmp-timestamp(322)</ref>
      <ref source="CONFIRM" url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10053">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10053</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num=""/>
      </prod>
      <prod name="mac_os_x" vendor="apple">
        <vers num=""/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="tru64" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num=""/>
      </prod>
      <prod name="os2" vendor="ibm">
        <vers num=""/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num=""/>
      </prod>
      <prod name="all_windows" vendor="microsoft">
        <vers num="abstract_cpe"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num=""/>
      </prod>
      <prod name="sco_unix" vendor="santa_cruz_operation">
        <vers num=""/>
      </prod>
      <prod name="bsdos" vendor="windriver">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0525" seq="1999-0525" published="1997-01-01" modified="2014-11-24" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">IP traceroute is allowed from arbitrary hosts.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <loss_types>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0526" seq="1999-0526" published="1997-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704969">VU#704969</ref>
    </refs>
    <vuln_soft>
      <prod name="x11" vendor="x.org">
        <vers num="7.1_1.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0527" seq="1999-0527" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The permissions for system-critical data in an anonymous FTP account are inappropriate.  For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0528" seq="1999-0528" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0529" seq="1999-0529" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0530" seq="1999-0530" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system is operating in "promiscuous" mode which allows it to perform packet sniffing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0531" seq="1999-0531" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">This functionality should be disabled, because these commands can be used for attack reconnaissance.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0532" seq="1999-0532" published="1997-07-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">A DNS server allows zone transfers.</descript>
    </desc>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0533" seq="1999-0533" published="1997-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A DNS server allows inverse queries.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0534" seq="1999-0534" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0535" seq="1999-0535" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0537" seq="1999-0537" published="1998-04-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6.0.2900"/>
      </prod>
      <prod name="communicator" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0539" seq="1999-0539" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A trust relationship exists between two Unix hosts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0541" seq="1999-0541" published="1997-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A password for accessing a WWW URL is guessable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0546" seq="1999-0546" published="1998-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Windows NT guest account is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0547" seq="1999-0547" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An SSH server allows authentication through the .rhosts file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0548" seq="1999-0548" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A superfluous NFS server is running, but it is not importing or exporting any file systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0549" seq="1999-0549" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT automatically logs in an administrator upon rebooting.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0550" seq="1999-0550" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A router's routing tables can be obtained from arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0551" seq="1999-0551" published="1998-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9804-078">HPSBUX9804-078</ref>
    </refs>
    <vuln_soft>
      <prod name="openmail" vendor="hp">
        <vers num="4.1"/>
        <vers num="5.1"/>
        <vers num="5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0554" seq="1999-0554" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NFS exports system-critical data to the world, e.g. / or a password file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0555" seq="1999-0555" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Unix account with a name other than "root" has UID 0, i.e. root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0556" seq="1999-0556" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Two or more Unix accounts have the same UID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0559" seq="1999-0559" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system-critical Unix file or directory has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0560" seq="1999-0560" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system-critical Windows NT file or directory has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0561" seq="1999-0561" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IIS has the #exec function enabled for Server Side Include (SSI) files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0562" seq="1999-0562" published="1997-01-01" modified="2017-10-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The registry in Windows NT can be accessed remotely by users who are not administrators.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1023">oval:org.mitre.oval:def:1023</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0564" seq="1999-0564" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0565" seq="1999-0565" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Sendmail alias allows input to be piped to a program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0566" seq="1999-0566" published="1997-08-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0568" seq="1999-0568" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rpc.admind in Solaris is not running in a secure mode.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0569" seq="1999-0569" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0570" seq="1999-0570" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0571" seq="1999-0571" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0572" seq="1999-0572" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0575" seq="1999-0575" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0576" seq="1999-0576" published="1997-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0577" seq="1999-0577" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0578" seq="1999-0578" published="1999-01-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0579" seq="1999-0579" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0580" seq="1999-0580" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0581" seq="1999-0581" published="1999-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0582" seq="1999-0582" published="1997-01-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0583" seq="1999-0583" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">There is a one-way or two-way trust relationship between Windows NT domains.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0584" seq="1999-0584" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT file system is not NTFS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0585" seq="1999-0585" published="2000-07-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A Windows NT administrator account has the default name of Administrator.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1" edition="sp1"/>
        <vers num="3.5.1" edition="sp2"/>
        <vers num="3.5.1" edition="sp3"/>
        <vers num="3.5.1" edition="sp5"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0586" seq="1999-0586" published="1999-01-01" modified="2014-11-04" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">A network service is running on a nonstandard port.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0587" seq="1999-0587" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0588" seq="1999-0588" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A filter in a router or firewall allows unusual fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0589" seq="1999-0589" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system-critical Windows NT registry key has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0590" seq="1999-0590" published="2000-06-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system does not present an appropriate legal message or warning to a user who is accessing it.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num=""/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1" edition="sp1"/>
        <vers num="3.5.1" edition="sp2"/>
        <vers num="3.5.1" edition="sp3"/>
        <vers num="3.5.1" edition="sp5"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0591" seq="1999-0591" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An event log in Windows NT has inappropriate access permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0592" seq="1999-0592" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Logon box of a Windows NT system displays the name of the last user who logged in.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0593" seq="1999-0593" published="1999-01-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.9" CVSS_base_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://technet.microsoft.com/en-us/library/cc722469.aspx">http://technet.microsoft.com/en-us/library/cc722469.aspx</ref>
      <ref source="MISC" url="http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true">http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1291">nt-shutdown-without-logon(1291)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0594" seq="1999-0594" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0595" seq="1999-0595" published="2000-01-20" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0596" seq="1999-0596" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT log file has an inappropriate maximum size or retention period.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0597" seq="1999-0597" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0598" seq="1999-0598" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0599" seq="1999-0599" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0600" seq="1999-0600" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not verify the checksum on a packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0601" seq="1999-0601" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0602" seq="1999-0602" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A network intrusion detection system (IDS) does not properly reassemble fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0603" seq="1999-0603" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0604" seq="1999-0604" published="1999-04-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod name="selena_sol_webstore" vendor="selena_sol">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0605" seq="1999-0605" published="1999-04-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An incorrect configuration of the Order Form 1.0 shopping cart  CGI program could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod name="merchant_order_form" vendor="austin_contract_computing">
        <vers num="1.0"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0606" seq="1999-0606" published="1999-04-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An incorrect configuration of the EZMall 2000 shopping cart  CGI program "mall2000.cgi" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod name="ezmall" vendor="seaside_enterprises">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0607" seq="1999-0607" published="1999-04-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod name="quikstore" vendor="i-soft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0608" seq="1999-0608" published="1999-04-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
      <ref source="CONFIRM" url="http://www.pdgsoft.com/Security/security.html.">http://www.pdgsoft.com/Security/security.html.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3857">pdgsoftcart-misconfig(3857)</ref>
    </refs>
    <vuln_soft>
      <prod name="pdg_shopping_cart" vendor="pdgsoft">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0609" seq="1999-0609" published="1999-04-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod name="softcart" vendor="mercantec">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0610" seq="1999-0610" published="1999-04-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An incorrect configuration of the Webcart CGI program could disclose private information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod name="webcart" vendor="mountain_network_systems">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0611" seq="1999-0611" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system-critical Windows NT registry key has an inappropriate value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0612" seq="1999-0612" published="1997-03-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">A version of finger is running that exposes valid user information to any entity on the network.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The FTP Service should be disabled because it could reveal information about a host's users, which could be used as reconnaissance information for attacks.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="finger_service" vendor="gnu">
        <vers num=""/>
      </prod>
      <prod name="fingerd" vendor="gnu">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0613" seq="1999-0613" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The rpc.sprayd service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">rpc.sprayd is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0614" seq="1999-0614" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The FTP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The FTP Service is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  Secure alternatives that encrypt communications are available.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0615" seq="1999-0615" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The SNMP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">SNMPv3 is a secure protocol for management of networked systems, provided the cryptographic security mechanisms are used.  SNMPv1 and SNMPv2 are unsecured protocols for Internet facing systems and should  only be used on a trusted network segment.  For all versions, the software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0616" seq="1999-0616" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The TFTP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The TFTP Service is an unsecured protocol and it should used only on a limited basis on rare occasion to provide a specific functional requirement, otherwise disabled.  Secure alternatives are available.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0617" seq="1999-0617" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The SMTP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The SMTP Service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted) and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0618" seq="1999-0618" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The rexec service is running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0619" seq="1999-0619" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The Telnet service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The Telnet Service is an unsecured and obsolete protocol and it should be disabled.  Secure alternatives such as SSH are available.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0620" seq="1999-0620" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A component service related to NIS is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">These protocols, such as RPC ypbind, yppasswd, ypserv, ypupdated, and ypxfrd, are unsecured protocols for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0621" seq="1999-0621" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A component service related to NETBIOS is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">This component service should not be allowed to communicate over untrusted networks, such as the Internet, because it is an unsecured protocol (e.g., communications not encrypted).   The software should be patched and configured properly.</sol>
    </sols>
    <refs>
      <ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1024" sig="1">oval:org.mitre.oval:def:1024</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0622" seq="1999-0622" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A component service related to DNS service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">DNS is a critical network service.  It should be fully patched and properly configured for Internet facing servers to avoid common attacks such as DNS spoofing, poisoning, and unauthorized zone transfers.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0623" seq="1999-0623" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The X Windows service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The XWindows service is an unsecured protocol for Internet facing system and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0624" seq="1999-0624" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The rstat/rstatd service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">These are unsecured and obsolete protocols and they should be disabled.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0625" seq="1999-0625" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The rpc.rquotad service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">rpc.rquotad is an unsecured and obsolete protocol and it should be disabled.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0626" seq="1999-0626" published="1997-01-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">A version of rusers is running that exposes valid user information to any entity on the network.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">rusers is an unsecured and obsolete protocol and it should be disabled.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="rpc.ruserd" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0627" seq="1999-0627" published="1992-03-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The rexd service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0628" seq="1999-0628" published="1997-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The rwho/rwhod service is running, which exposes machine status and user information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0629" seq="1999-0629" published="1999-01-01" modified="2010-12-01" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The ident/identd service is running.</descript>
    </desc>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0630" seq="1999-0630" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The NT Alerter and Messenger services are running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0631" seq="1999-0631" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The NFS service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">NFS Service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted) and should only be used on a trusted managed network, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0632" seq="1999-0632" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The RPC portmapper service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The RPC portmapper service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0633" seq="1999-0633" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The HTTP/WWW service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The software should be patched and configured properly.  SSL/TLS should be used to protect transmissions of sensitive data.  The presence of HTTP may be an indication that an web application server is running on the system.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0634" seq="1999-0634" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The SSH service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">SSH is a secure protocol, provided it is fully patched, properly configured, and uses FIPS approved algorithms.  SSH version 2 is preferred over SSH version 1 because of known flaws in version 1.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0635" seq="1999-0635" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The echo service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The Echo Service is an unsecured and obsolete protocol and it should be disabled.  Historically it has been used to perform denial of service attacks.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0636" seq="1999-0636" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The discard service is running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0637" seq="1999-0637" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The systat service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The systat service is an unsecured and obsolete protocol and it should be disabled because it can reveal information about a host's operations.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0638" seq="1999-0638" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The daytime service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The daytime service is an unsecured and obsolete protocol and it should be disabled.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0639" seq="1999-0639" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The chargen service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">chargen service is an unsecured and obsolete protocol and it should be disabled.  Historically it has been used to perform denial of service attacks.  Ping and traceroute can be used to provide the same functionality.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0640" seq="1999-0640" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Gopher service is running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0641" seq="1999-0641" published="1999-01-01" modified="2007-07-13" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">The UUCP service is running.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The UUCP Service is an unsecured and obsolete protocol and it should be disabled.</sol>
    </sols>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0642" seq="1999-0642" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A POP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">POP3 is an unsecured protocol for Internet facing systems that does not encrypt its transmissions.  POP3 should be tunneled over SSL/TLS or another encrypted tunnel.  The software should be patched and configured properly.  Earlier versions of POP, such as POP2, are unsecured and obsolete, and should be disabled.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0643" seq="1999-0643" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The IMAP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">IMAP Service is an unsecured protocol for Internet facing systems that does not encrypt its transmissions.  IMAP should be tunneled over SSL/TLS or another encrypted tunnel.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0644" seq="1999-0644" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The NNTP news service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">NNTP news service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted).  It could be tunneled over SSL/TLS.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0645" seq="1999-0645" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The IRC service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">IRC Service is an unsecured protocol that typically does not authenticate the identity of users and does not encrypt its network communications.  IRC is not commonly deployed on enterprise networks.  If an organization decides to use it, it should be patched and configured properly, otherwise it should be disabled.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0646" seq="1999-0646" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The LDAP service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The software should be patched and configured properly to prevent information disclosure.  It can be tunneled over SSL/TLS.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0647" seq="1999-0647" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The bootparam (bootparamd) service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The bootparam service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0648" seq="1999-0648" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The X25 service is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">X25 is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0649" seq="1999-0649" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "The FSP service is running."</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0650" seq="1999-0650" published="1999-01-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The netstat service is running, which provides sensitive information to remote attackers.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/72">netstat(72)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0651" seq="1999-0651" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The rsh/rlogin service is running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0652" seq="1999-0652" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A database service is running, e.g. a SQL server, Oracle, or mySQL."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <sols>
      <sol source="nvd">The software should be patched and configured properly to prevent information leakage and unauthorized access.</sol>
    </sols>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0653" seq="1999-0653" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A component service related to NIS+ is running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0654" seq="1999-0654" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The OS/2 or POSIX subsystem in NT is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0655" seq="1999-0655" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  Notes: the former description is: "A service may include useful information in its banner or help function (such as the name and version), making it useful for information gathering activities."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0656" seq="1999-0656" published="1999-01-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638">http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/348">linux-ugidd(348)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0657" seq="1999-0657" published="1999-01-01" modified="2007-07-21" severity="Low" CVSS_version="2.0" CVSS_score="0.0" CVSS_base_score="0.0" CVSS_impact_subscore="0.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)">
    <desc>
      <descript source="cve">WinGate is being used.</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0658" seq="1999-0658" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "DCOM is running."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0659" seq="1999-0659" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0660" seq="1999-0660" published="1999-01-01" modified="2008-08-01" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  It might be more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: "A hacker utility, back door, or Trojan Horse is installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc."</descript>
    </desc>
    <impacts>
      <impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact>
    </impacts>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0661" seq="1999-0661" published="1999-01-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=102820843403741&amp;w=2">20020801 trojan horse in recent openssh (version 3.4 portable 1)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=102821663814127&amp;w=2">20020801 OpenSSH Security Advisory:  Trojaned Distribution Files</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/294539">20021009 Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1994-07.html">CA-1994-07</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1994-14.html">CA-1994-14</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1999-01.html">CA-1999-01</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1999-02.html">CA-1999-02</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2002-28.html">CA-2002-28</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10313.php">sendmail-backdoor(10313)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5921">5921</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0662" seq="1999-0662" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0663" seq="1999-0663" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0664" seq="1999-0664" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An application-critical Windows NT registry key has inappropriate permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0665" seq="1999-0665" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An application-critical Windows NT registry key has an inappropriate value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0667" seq="1999-0667" published="1997-09-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="arp_protocol" vendor="arp_protocol">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0668" seq="1999-0668" published="1999-08-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240308">Q240308</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/598">598</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-032">MS99-032</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0669" seq="1999-0669" published="1999-09-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml" adv="1">J-064</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0670" seq="1999-0670" published="1999-09-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-032">MS99-032</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0671" seq="1999-0671" published="1999-08-03" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ToxSoft NextFTP client through CWD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/572">572</ref>
    </refs>
    <vuln_soft>
      <prod name="nextftp" vendor="toxsoft">
        <vers num="1.82"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0672" seq="1999-0672" published="1999-08-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/573">573</ref>
    </refs>
    <vuln_soft>
      <prod name="chocoa" vendor="fujitsu">
        <vers num="1.0beta7r"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0673" seq="1999-0673" published="1999-08-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ALMail32 POP3 client via From: or To: headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/574">574</ref>
    </refs>
    <vuln_soft>
      <prod name="almail32" vendor="crear">
        <vers num="1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0674" seq="1999-0674" published="1999-08-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-067.shtml">J-067</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/570" adv="1" patch="1">570</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0675" seq="1999-0675" published="1999-08-09" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/23615">19990809 FW1 UDP Port 0 DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/576">576</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0676" seq="1999-0676" published="1999-08-09" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/575">575</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19990809134220.A1191@hades.chaoz.org">19990808 sdtcm_convert</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0677" seq="1999-0677" published="1999-08-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The WebRamp web administration utility has a default password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/577">577</ref>
    </refs>
    <vuln_soft>
      <prod name="webramp_200i" vendor="ramp_networks">
        <vers num="1.0"/>
      </prod>
      <prod name="webramp_m3" vendor="ramp_networks">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0678" seq="1999-0678" published="1999-01-17" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/318">318</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0679" seq="1999-0679" published="1999-08-13" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.efnet.org/archive/servers/hybrid/ChangeLog">http://www.efnet.org/archive/servers/hybrid/ChangeLog</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/581">581</ref>
    </refs>
    <vuln_soft>
      <prod name="hybrid_ircd" vendor="hybrid_network">
        <vers num="5.03p7"/>
        <vers num="6.0beta58" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0680" seq="1999-0680" published="1999-08-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238600">Q238600</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-057.shtml">J-057</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/571" adv="1" patch="1">571</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-028">MS99-028</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0681" seq="1999-0681" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999-q3/0381.html" adv="1">19990807 Crash FrontPage Remotely...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/568" adv="1">568</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3117">frontpage-pws-dos(3117)</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num="97"/>
        <vers num="98"/>
      </prod>
      <prod name="personal_web_server" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0682" seq="1999-0682" published="1999-08-06" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237927">Q237927</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-056.shtml">J-056</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/567">567</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-027">MS99-027</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0683" seq="1999-0683" published="1999-07-30" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Gauntlet Firewall via a malformed ICMP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/556" adv="1" patch="1">556</ref>
    </refs>
    <vuln_soft>
      <prod name="gauntlet_firewall" vendor="network_associates">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0684" seq="1999-0684" published="1999-04-19" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Sendmail 8.8.6 in HPUX.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sendmail" vendor="hp">
        <vers num="8.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0685" seq="1999-0685" published="1999-09-02" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/618">618</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.5"/>
        <vers num="4.06"/>
        <vers num="4.51"/>
        <vers num="4.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0686" seq="1999-0686" published="1999-05-07" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-046.shtml">J-046</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-098">HPSBUX9906-098</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num=""/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0687" seq="1999-0687" published="1999-09-13" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-001.shtml">K-001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/637">637</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
    </refs>
    <vuln_soft>
      <prod name="cde" vendor="cde">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.120"/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num="4.0d"/>
        <vers num="4.0f"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0688" seq="1999-0688" published="1999-07-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/545">545</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-101">HPSBUX9907-101</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.24"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0689" seq="1999-0689" published="1999-09-13" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/636">636</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1880">oval:org.mitre.oval:def:1880</ref>
    </refs>
    <vuln_soft>
      <prod name="cde" vendor="cde">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.120"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0690" seq="1999-0690" published="1999-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP CDE program includes the current directory in root's PATH variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-053.shtml" adv="1">J-053</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-100">HPSBUX9907-100</ref>
    </refs>
    <vuln_soft>
      <prod name="cde" vendor="cde">
        <vers num=""/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0691" seq="1999-0691" published="1999-09-13" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/635">635</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3078">oval:org.mitre.oval:def:3078</ref>
    </refs>
    <vuln_soft>
      <prod name="cde" vendor="cde">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num="4.0d"/>
        <vers num="4.0e"/>
        <vers num="4.0f"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0692" seq="1999-0692" published="1999-07-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990701-01-P">19990701-01-P</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-052.shtml">J-052</ref>
    </refs>
    <vuln_soft>
      <prod name="unicos" vendor="cray">
        <vers num=""/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0693" seq="1999-0693" published="2000-03-02" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/641">641</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4374">oval:org.mitre.oval:def:4374</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0694" seq="1999-0694" published="1999-08-11" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in AIX ptrace system call allows local users to crash the system.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-055.shtml" adv="1" patch="1">J-055</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0695" seq="1999-0695" published="2000-04-11" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/620">620</ref>
    </refs>
    <vuln_soft>
      <prod name="powerdynamo" vendor="sybase">
        <vers num="3.0.652"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0696" seq="1999-0696" published="1999-07-01" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/188">00188</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-051.shtml">J-051</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9908-102">HPSBUX9908-102</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.24"/>
        <vers num="11.00"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.3"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0697" seq="1999-0697" published="1999-09-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SCO Doctor allows local users to gain root privileges through a Tools option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/621">621</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0698" seq="1999-0698" published="1999-01-01" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0699" seq="1999-0699" published="2000-04-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/623">623</ref>
    </refs>
    <vuln_soft>
      <prod name="sapphire_web" vendor="bluestone">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0700" seq="1999-0700" published="1999-07-29" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237185">Q237185</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-026">MS99-026</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0701" seq="1999-0701" published="2000-04-11" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q173039">Q173039</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/626">626</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-036">MS99-036</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0702" seq="1999-0702" published="1999-09-10" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241361">Q241361</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/627">627</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-037">MS99-037</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0703" seq="1999-0703" published="1999-08-03" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-066.shtml">J-066</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.2"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.2"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0704" seq="1999-0704" published="1999-09-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/614">614</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.1"/>
        <vers num="4.0.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0705" seq="1999-0705" published="1999-09-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in INN inews program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/616">616</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num=""/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0706" seq="1999-0706" published="2000-04-27" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/583">583</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="1.5.1"/>
        <vers num="1.7"/>
        <vers num="1.7.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0707" seq="1999-0707" published="1999-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-050.shtml" adv="1">J-050</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/493">493</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-099">HPSBUX9906-099</ref>
    </refs>
    <vuln_soft>
      <prod name="visualize_conference_ftp" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0708" seq="1999-0708" published="1999-09-21" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/651">651</ref>
    </refs>
    <vuln_soft>
      <prod name="cfingerd" vendor="infodrom">
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0710" seq="1999-0710" published="1999-07-25" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-576">DSA-576</ref>
      <ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid">http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-025.html">RHSA-1999:025</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-489.html">RHSA-2005:489</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2059">2059</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2385">http-cgi-cachemgr(2385)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0711" seq="1999-0711" published="1999-04-29" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92609807906778&amp;w=2">19990506 Oracle Security Followup, patch and FAQ: setuid on oratclsh</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?t=92550157100002&amp;w=2&amp;r=1">19990430 *Huge* security hole in Oracle 8.0.5 with Intellegent agent installed</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.0.5.1"/>
        <vers num="8.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0712" seq="1999-0712" published="1999-04-27" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="coas" vendor="caldera">
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0713" seq="1999-0713" published="1999-06-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-044.shtml">J-044</ref>
    </refs>
    <vuln_soft>
      <prod name="cde" vendor="cde">
        <vers num=""/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="5"/>
      </prod>
      <prod name="afs" vendor="transarc">
        <vers num=""/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0714" seq="1999-0714" published="1999-02-15" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in Compaq Tru64 UNIX edauth command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="3.2g"/>
        <vers num="4.0"/>
        <vers num="4.0a"/>
        <vers num="4.0b"/>
        <vers num="4.0c"/>
        <vers num="4.0d"/>
        <vers num="4.0e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0715" seq="1999-0715" published="1999-05-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230677">Q230677</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-016">MS99-016</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0716" seq="1999-0716" published="1999-05-17" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231605">Q231605</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-015">MS99-015</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0717" seq="1999-0717" published="1999-05-07" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231304">Q231304</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-014">MS99-014</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0718" seq="1999-0718" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9908&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5534">19990823 IBM Gina security warning</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/608" adv="1" patch="1">608</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3166">ibm-gina-group-add(3166)</ref>
    </refs>
    <vuln_soft>
      <prod name="gina" vendor="ibm">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0719" seq="1999-0719" published="1999-08-05" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/563">563</ref>
    </refs>
    <vuln_soft>
      <prod name="gnumeric" vendor="gnu">
        <vers num="0.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0720" seq="1999-0720" published="1999-08-23" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/597">597</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=lcamtuf.4.05.9907041223290.355-300000@nimue.ids.pl">19990823 [Linux] glibc 2.1.x / wu-ftpd &lt;=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0721" seq="1999-0721" published="1999-07-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231457">Q231457</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-020">MS99-020</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0722" seq="1999-0722" published="1999-08-08" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/558">558</ref>
    </refs>
    <vuln_soft>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0723" seq="1999-0723" published="1999-06-23" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233323">Q233323</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/478">478</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-021">MS99-021</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0724" seq="1999-0724" published="1999-08-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0725" seq="1999-0725" published="1999-08-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233335">Q233335</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/477" adv="1">477</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-022">MS99-022</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2302" adv="1">iis-double-byte-code-page(2302)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0" edition="::ja"/>
        <vers num="3.0" edition="::ko"/>
        <vers num="3.0" edition="::zh"/>
        <vers num="4.0" edition="::ja"/>
        <vers num="4.0" edition="::ko"/>
        <vers num="4.0" edition="::zh"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0726" seq="1999-0726" published="1999-06-30" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234557">Q234557</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/499">499</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-023">MS99-023</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0727" seq="1999-0727" published="1999-08-06" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0728" seq="1999-0728" published="1999-07-06" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q236359">Q236359</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-024">MS99-024</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0729" seq="1999-0729" published="2001-03-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-061.shtml" adv="1">J-061</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/601" adv="1">601</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise34.php" adv="1">19990823 Denial of Service Attack against Lotus Notes Domino Server 4.6</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_server" vendor="ibm">
        <vers num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0730" seq="1999-0730" published="1999-06-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0731" seq="1999-0731" published="1999-06-23" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The KDE klock program allows local users to unlock a session using malformed input.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/489">489</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.3"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0732" seq="1999-0732" published="1999-08-19" modified="2016-09-16" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0733" seq="1999-0733" published="1999-06-26" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/490">490</ref>
    </refs>
    <vuln_soft>
      <prod name="workstation" vendor="vmware">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0734" seq="1999-0734" published="1999-08-19" modified="2019-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3133">ciscosecure-read-write(3133)</ref>
      <ref source="CISCO" url="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-19990819-dbaccess">19990819 CiscoSecure Access Control Server for UNIX Remote Administration Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="ciscosecure" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0735" seq="1999-0735" published="2000-01-04" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA1999015_01.html">RHSA-1999:015-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/300" patch="1">300</ref>
    </refs>
    <vuln_soft>
      <prod name="k-mail" vendor="kde">
        <vers num="1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0736" seq="1999-0736" published="1999-05-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013">MS99-013</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A932">oval:org.mitre.oval:def:932</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0737" seq="1999-0737" published="1999-05-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013">MS99-013</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0738" seq="1999-0738" published="1999-05-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013">MS99-013</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0739" seq="1999-0739" published="1999-05-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013">MS99-013</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0740" seq="1999-0740" published="1999-08-19" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/594">594</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0741" seq="1999-0741" published="1999-08-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/593">593</ref>
    </refs>
    <vuln_soft>
      <prod name="crownnet_unix_utilities" vendor="qms">
        <vers num="2060"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0742" seq="1999-0742" published="1999-06-22" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Debian mailman package uses weak authentication, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/480">480</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0743" seq="1999-0743" published="1999-08-20" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Trn allows local users to overwrite other users' files via symlinks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3144">trn-symlinks(3144)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0744" seq="1999-0744" published="2000-01-04" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/603">603</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num=""/>
      </prod>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0745" seq="1999-0745" published="1999-08-18" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-059.shtml">J-059</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/590">590</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="2.2.1"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0746" seq="1999-0746" published="1999-08-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/587">587</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.2"/>
        <vers num="3.6"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0747" seq="1999-0747" published="1999-08-18" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/589">589</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSI.4.10.9908170253560.19291-100000@saturn.psn.net">19990816 Symmetric Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0748" seq="1999-0748" published="1999-06-24" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Red Hat net-tools package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0749" seq="1999-0749" published="1999-08-16" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/586">586</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-033">MS99-033</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0750" seq="1999-0750" published="1999-09-13" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/630">630</ref>
    </refs>
    <vuln_soft>
      <prod name="hotmail" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0751" seq="1999-0751" published="1999-09-13" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/631">631</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3256">netscape-accept-bo(3256)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.5.1"/>
        <vers num="3.6" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0752" seq="1999-0752" published="1999-07-06" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0753" seq="1999-0753" published="1999-08-17" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/591">591</ref>
    </refs>
    <vuln_soft>
      <prod name="msql" vendor="hughes">
        <vers num="2.0"/>
        <vers num="2.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0754" seq="1999-0754" published="1999-05-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-011.0.txt">CSSA-1999-011.0</ref>
      <ref source="MISC" url="http://www.redhat.com/corp/support/errata/inn99_05_22.html" adv="1" patch="1">http://www.redhat.com/corp/support/errata/inn99_05_22.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/255">255</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0755" seq="1999-0755" published="1999-05-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230681">Q230681</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-017">MS99-017</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0756" seq="1999-0756" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=10968&amp;Method=Full" adv="1">ASB99-07</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2207">coldfusion-admin-dos(2207)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0757" seq="1999-0757" published="2001-03-12" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=10969&amp;Method=Full" adv="1">ASB99-08</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2208">coldfusion-encryption(2208)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0758" seq="1999-0758" published="2001-03-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.5.1"/>
      </prod>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0759" seq="1999-0759" published="1999-09-13" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FuseMAIL POP service via long USER and PASS commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.crosswinds.net/~fuseware/faq.html#8">http://www.crosswinds.net/~fuseware/faq.html#8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/634">634</ref>
    </refs>
    <vuln_soft>
      <prod name="fusemail" vendor="fuseware">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0760" seq="1999-0760" published="2001-03-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=11714&amp;Method=Full">ASB99-10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/550" adv="1" patch="1">550</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3288">coldfusion-server-cfml-tags(3288)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0761" seq="1999-0761" published="2000-09-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/644">644</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0762" seq="1999-0762" published="1999-05-24" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.6" edition=":windows_95"/>
        <vers num="4.x"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0763" seq="1999-0763" published="1999-05-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0764" seq="1999-0764" published="1999-05-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">NetBSD allows ARP packets to overwrite static ARP entries.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0765" seq="1999-0765" published="1999-05-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A">19990501-01-A</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/262">262</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0766" seq="1999-0766" published="1999-10-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240346">Q240346</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/600">600</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-031">MS99-031</ref>
    </refs>
    <vuln_soft>
      <prod name="java_virtual_machine" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0767" seq="1999-0767" published="1999-09-08" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0768" seq="1999-0768" published="1999-08-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/602">602</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0" edition=":i386"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0769" seq="1999-0769" published="1999-08-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref>
    </refs>
    <vuln_soft>
      <prod name="vixie_cron" vendor="paul_vixie">
        <vers num="3.0_pl1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.2"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0770" seq="1999-0770" published="1999-07-29" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/549" adv="1" patch="1">549</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0771" seq="1999-0771" published="1999-05-26" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="insight_management_agent" vendor="compaq">
        <vers num=""/>
      </prod>
      <prod name="power_management" vendor="compaq">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0772" seq="1999-0772" published="1999-06-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="insight_management_agent" vendor="compaq">
        <vers num=""/>
      </prod>
      <prod name="power_management" vendor="compaq">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0773" seq="1999-0773" published="1999-05-11" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris lpset program allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905B&amp;L=bugtraq&amp;P=R2017">19990511 Solaris2.6 and 2.7 lpset overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0774" seq="1999-0774" published="1999-08-31" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/617">617</ref>
    </refs>
    <vuln_soft>
      <prod name="mars_nwe" vendor="martin_stover">
        <vers num="0.99"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0775" seq="1999-0775" published="1999-06-10" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.2(14)gs2"/>
        <vers num="11.2(15)g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0776" seq="1999-0776" published="1999-05-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9905&amp;L=NTBUGTRAQ&amp;P=R1533" adv="1">19990506 ".."-hole in Alibaba 2.0</ref>
    </refs>
    <vuln_soft>
      <prod name="alibaba" vendor="computer_software_manufaktur">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0777" seq="1999-0777" published="1999-09-23" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241407">Q241407</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242559">Q242559</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/658">658</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-039">MS99-039</ref>
    </refs>
    <vuln_soft>
      <prod name="commercial_internet_system" vendor="microsoft">
        <vers num="2.5"/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0778" seq="1999-0778" published="1999-06-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/488">488</ref>
    </refs>
    <vuln_soft>
      <prod name="accelerated-x_server" vendor="xi_graphics">
        <vers num="4"/>
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0779" seq="1999-0779" published="1998-09-03" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in HP-UX SharedX recserv program.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9810-086">HPSBUX9810-086</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0780" seq="1999-0780" published="1998-11-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="kde" vendor="kde">
        <vers num="1.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0781" seq="1999-0781" published="1998-11-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="kde" vendor="kde">
        <vers num="1.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0782" seq="1999-0782" published="1998-11-18" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="kde" vendor="kde">
        <vers num="1.0"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0783" seq="1999-0783" published="1998-06-16" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-057.shtml">I-057</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0784" seq="1999-0784" published="2001-03-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1998_4/0764.html" adv="1">19981228 Oracle8 TNSLSNR DoS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999_1/0056.html" adv="1">19990104 Re: Fw:"NERP" DoS attack possible in Oracle</ref>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998/msg00536.html">19980827 NERP DoS attack possible in Oracle</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="7.1.4"/>
        <vers num="7.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0785" seq="1999-0785" published="1999-05-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/254">254</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0786" seq="1999-0786" published="1999-09-22" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/659">659</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0787" seq="1999-0787" published="1999-09-17" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The SSH authentication agent follows symlinks via a UNIX domain socket.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93832856804415&amp;w=2">19990924 [Fwd: Truth about ssh 1.2.27 vulnerability]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/660">660</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0788" seq="1999-0788" published="1999-09-26" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Arkiea nlservd allows remote attackers to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93837184228248&amp;w=2">19990924 Multiple vendor Knox Arkiea local root/remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/662">662</ref>
    </refs>
    <vuln_soft>
      <prod name="arkeia" vendor="knox_software">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0789" seq="1999-0789" published="1999-09-28" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AIX ftpd in the libc library.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-072.shtml">J-072</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/679">679</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0790" seq="1999-0790" published="2000-04-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A remote attacker can read information from a Netscape user's cache via JavaScript.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://home.netscape.com/security/notes/jscachebrowsing.html">http://home.netscape.com/security/notes/jscachebrowsing.html</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0791" seq="1999-0791" published="1999-10-06" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/695">695</ref>
    </refs>
    <vuln_soft>
      <prod name="hsmp" vendor="hybrid_network">
        <vers num=""/>
      </prod>
      <prod name="cable_modem" vendor="hybrid_network">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0792" seq="1999-0792" published="1998-09-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www2.merton.ox.ac.uk/~security/rootshell/0022.html">http://www2.merton.ox.ac.uk/~security/rootshell/0022.html</ref>
    </refs>
    <vuln_soft>
      <prod name="routermate" vendor="osicom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0793" seq="1999-0793" published="1999-11-17" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-043">MS99-043</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0794" seq="1999-0794" published="1999-10-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241900">Q241900</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241901">Q241901</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241902">Q241902</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-044">MS99-044</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0795" seq="1999-0795" published="1998-03-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0796" seq="1999-0796" published="1998-05-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.0"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0797" seq="1999-0797" published="1998-06-29" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-070.shtml">I-070</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0798" seq="1999-0798" published="1998-12-04" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91278867118128&amp;w=2">19981204 bootpd remote vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num=""/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num=""/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num=""/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0799" seq="1999-0799" published="1997-06-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bootpd" vendor="cmu">
        <vers num="2.4.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0800" seq="1999-0800" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00332.html" adv="1">19990211 ACFUG List: Alert: Allaire Forums GetFile bug</ref>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=9602&amp;Method=Full" adv="1" patch="1">ASB99-05</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1748">allaire-forums-file-read(1748)</ref>
    </refs>
    <vuln_soft>
      <prod name="forums" vendor="allaire">
        <vers num="2.0.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0801" seq="1999-0801" published="1999-04-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/2075.php">bmc-patrol-frames(2075)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
    </refs>
    <vuln_soft>
      <prod name="patrol_agent" vendor="bmc">
        <vers num="3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0802" seq="1999-0802" published="1999-05-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231450">Q231450</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-018">MS99-018</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0803" seq="1999-0803" published="1999-05-25" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92765973207648&amp;w=2">19990525 IBM eNetwork Firewall for AIX</ref>
    </refs>
    <vuln_soft>
      <prod name="aix_enetwork_firewall" vendor="ibm">
        <vers num="3.2"/>
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0804" seq="1999-0804" published="1999-06-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/302">302</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":i386"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0805" seq="1999-0805" published="2001-03-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999_2/0439.html" adv="1">19990512 DoS with Netware 4.x's TTS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2184">novell-tts-dos(2184)</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="4.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0806" seq="1999-0806" published="1999-05-10" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris dtprintinfo program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0807" seq="1999-0807" published="1999-05-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="directory_server" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0808" seq="1999-0808" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz" patch="1">ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-053.shtml" adv="1" patch="1">I-053</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925960&amp;w=2">19980518 DHCP 1.0 and 2.0 SECURITY ALERT! (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod name="dhcp_client" vendor="isc">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0809" seq="1999-0809" published="1999-07-09" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0810" seq="1999-0810" published="1999-07-21" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of service in Samba NETBIOS name service daemon (nmbd).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0811" seq="1999-0811" published="1999-07-21" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Samba smbd program via a malformed message command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/536">536</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0812" seq="1999-0812" published="2000-07-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0813" seq="1999-0813" published="1999-08-10" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cfingerd" vendor="infodrom">
        <vers num="1.4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0814" seq="1999-0814" published="1999-08-11" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-027.html">RHSA-1999:027</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0815" seq="1999-0815" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q196/2/70.asp" adv="1" patch="1">Q196270</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1974">nt-snmpagent-leak(1974)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A952">oval:org.mitre.oval:def:952</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1" edition=":server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0816" seq="1999-0816" published="1998-05-10" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621" adv="1">19980510 Security Vulnerability in Motorola CableRouters</ref>
    </refs>
    <vuln_soft>
      <prod name="motorola_cablerouter" vendor="motorola">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0817" seq="1999-0817" published="1999-09-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="lynx" vendor="university_of_kansas">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0818" seq="1999-0818" published="1999-11-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/831">831</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38433B7F5A.53F4SHADOWPENGUIN@fox.nightland.net">19991130 another hole of Solaris7 kcms_configure</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0819" seq="1999-0819" published="1999-12-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94398141118586&amp;w=2">19991130 NTmail and VRFY</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0820" seq="1999-0820" published="1999-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0821" seq="1999-0821" published="1999-11-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0822" seq="1999-0822" published="1999-11-30" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/830">830</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="3.0"/>
        <vers num="3.0b20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0823" seq="1999-0823" published="1999-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/839">839</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0824" seq="1999-0824" published="1999-11-30" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/833">833</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0825" seq="1999-0825" published="1999-12-03" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/849">849</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0826" seq="1999-0826" published="1999-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD angband allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/840">840</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0827" seq="1999-0827" published="1999-11-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="3.0.2"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="4.0" edition="a_mac_os"/>
        <vers num="4.0.1" edition="sp2"/>
        <vers num="4.1"/>
        <vers num="4.5"/>
        <vers num="5.0"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num="4.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0828" seq="1999-0828" published="1999-12-02" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/853">853</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0829" seq="1999-0829" published="1999-11-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">HP Secure Web Console uses weak encryption.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="secure_web_console" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0830" seq="1999-0830" published="1999-11-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SCO UnixWare Xsco command via a long argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0831" seq="1999-0831" published="1999-11-19" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Linux syslogd via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-035.0.txt">CSSA-1999-035.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/809">809</ref>
    </refs>
    <vuln_soft>
      <prod name="qube" vendor="cobalt">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod name="cobalt_raq" vendor="sun">
        <vers num="1.1"/>
      </prod>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0832" seq="1999-0832" published="1999-11-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt">CSSA-1999-033.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/1999/19991111">19991111 buffer overflow in nfs server</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_29.html">19991110 Security hole in nfs-server &lt; 2.2beta47 within nkita</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/rh42-errata-general.html#NFS">RHSA-1999:053-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/782">782</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl">19991109 undocumented bugs - nfsd</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0833" seq="1999-0833" published="1999-11-10" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in BIND 8.2 via NXT records.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.2"/>
        <vers num="8.2.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0834" seq="1999-0834" published="1999-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/843">843</ref>
    </refs>
    <vuln_soft>
      <prod name="rsaref" vendor="rsa">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0835" seq="1999-0835" published="1999-11-10" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of service in BIND named via malformed SIG records.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2"/>
        <vers num="7"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0836" seq="1999-0836" published="1998-12-02" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.22a">SB-99.22a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/842">842</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991202160111.20553.qmail@nwcst282.netaddress.usa.net">19991202 UnixWare 7 uidadmin exploit + discussion</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0837" seq="1999-0837" published="1999-11-10" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Denial of service in BIND by improperly closing TCP sessions via so_linger.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.2"/>
        <vers num="8.2.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0838" seq="1999-0838" published="1999-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/859">859</ref>
    </refs>
    <vuln_soft>
      <prod name="serv-u_ftp-server" vendor="deerfield">
        <vers num="2.5a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0839" seq="1999-0839" published="1999-11-29" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246972">Q246972</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/828">828</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-051">MS99-051</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5" edition=":windows_nt_4.0"/>
        <vers num="5.0" edition=":windows_95"/>
        <vers num="5.0" edition=":windows_98"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0840" seq="1999-0840" published="1999-11-30" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
      <ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/832">832</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3579">solaris-dtmail-overflow(3579)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3580">solaris-dtmailpr-overflow(3580)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0841" seq="1999-0841" published="1999-11-30" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
      <ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/832">832</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3732">cde-mailtool-bo(3732)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0842" seq="1999-0842" published="1999-11-29" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/827">827</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEAFCBAA.labs@ussrback.com">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="mail-gear" vendor="symantec">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0843" seq="1999-0843" published="1999-11-04" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0844" seq="1999-0844" published="1999-11-24" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in MDaemon WorldClient and WebConfig services via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/820">820</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/823">823</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="deerfield">
        <vers num="2.8.5"/>
        <vers num="2.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0845" seq="1999-0845" published="1999-11-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SCO su program allows local users to gain root access via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0846" seq="1999-0846" published="1999-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in MDaemon 2.7 via a large number of connection attempts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="mdaemon" vendor="deerfield">
        <vers num="2.8.5"/>
        <vers num="2.8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0847" seq="1999-0847" published="1999-11-29" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in free internet chess server (FICS) program, xboard.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="fics_program" vendor="freechess.org">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0848" seq="1999-0848" published="1999-11-10" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in BIND named via consuming more than "fdmax" file descriptors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.2"/>
        <vers num="8.2.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0849" seq="1999-0849" published="1999-11-10" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in BIND named via maxdname.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="4.9.5" edition="p1"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2" edition="p1"/>
        <vers num="8.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0850" seq="1999-0850" published="1999-12-02" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The default permissions for Endymion MailMan allow local users to read email or modify files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/845">845</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman_webmail" vendor="endymion">
        <vers num="3.0.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0851" seq="1999-0851" published="1999-11-10" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in BIND named via naptr.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2"/>
        <vers num="7"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0852" seq="1999-0852" published="1999-12-02" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/844">844</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0853" seq="1999-0853" published="1999-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/847">847</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.5.1"/>
        <vers num="3.6" edition="sp2"/>
      </prod>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0854" seq="1999-0854" published="1999-11-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref>
      <ref source="CONFIRM" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref>
    </refs>
    <vuln_soft>
      <prod name="ultimate_bulletin_board" vendor="infopop">
        <vers num="5.07"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0855" seq="1999-0855" published="1999-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD gdc program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/834">834</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0856" seq="1999-0856" published="1999-12-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0857" seq="1999-0857" published="1999-12-01" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FreeBSD gdc program allows local users to modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/835">835</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0858" seq="1999-0858" published="1999-12-02" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247333">Q247333</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/846">846</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-054">MS99-054</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0859" seq="1999-0859" published="1999-12-01" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0860" seq="1999-0860" published="1999-12-01" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0861" seq="1999-0861" published="1999-08-11" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q244613">Q244613</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-053">MS99-053</ref>
    </refs>
    <vuln_soft>
      <prod name="commercial_internet_system" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
      <prod name="site_server_commerce" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0862" seq="1999-0862" published="1999-12-02" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="postgresql" vendor="postgresql">
        <vers num="6.3.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0863" seq="1999-0863" published="1999-11-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0864" seq="1999-0864" published="1999-12-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/851">851</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991203020720.13115.qmail@nwcst289.netaddress.usa.net">19991202 UnixWare coredumps follow symlinks</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0865" seq="1999-0865" published="1999-12-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94426440413027&amp;w=2">19991203 CommuniGatePro 3.1 for NT DoS</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94454565726775&amp;w=2">19991203 CommuniGatePro 3.1 for NT Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/860">860</ref>
    </refs>
    <vuln_soft>
      <prod name="communigate_pro" vendor="stalker">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0866" seq="1999-0866" published="1999-12-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare xauto program allows local users to gain root privilege.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.24a">SB-99.24a</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/848">848</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0867" seq="1999-0867" published="1999-08-11" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238349">Q238349</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-058.shtml">J-058</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/579">579</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-029">MS99-029</ref>
    </refs>
    <vuln_soft>
      <prod name="commercial_internet_system" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0" edition="unknown:commerce"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0868" seq="1999-0868" published="1997-02-20" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="1.5.1"/>
      </prod>
      <prod name="news_server" vendor="netscape">
        <vers num="1.1"/>
      </prod>
      <prod name="goah_intrasv" vendor="nec">
        <vers num="r1.1"/>
      </prod>
      <prod name="goah_networksv" vendor="nec">
        <vers num="r1.2"/>
        <vers num="r2.2"/>
        <vers num="r3.1"/>
      </prod>
      <prod name="sparc" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0869" seq="1999-0869" published="1998-12-01" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-020">MS98-020</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0870" seq="1999-0870" published="1998-10-01" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-015">MS98-015</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0871" seq="1999-0871" published="1998-09-04" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-013">MS98-013</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3668">ie-crossframe-file-read(3668)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0872" seq="1999-0872" published="1999-08-25" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref>
    </refs>
    <vuln_soft>
      <prod name="vixie_cron" vendor="paul_vixie">
        <vers num="3.0_pl1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.2"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0873" seq="1999-0873" published="1999-10-30" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Skyfull mail server via MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref>
    </refs>
    <vuln_soft>
      <prod name="skyfull" vendor="sky_communications">
        <vers num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0874" seq="1999-0874" published="1999-06-16" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234905">Q234905</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-048.shtml">J-048</ref>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD06081999.html">AD06081999</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-019">MS99-019</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A915">oval:org.mitre.oval:def:915</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0875" seq="1999-0875" published="1999-08-11" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q216141">Q216141</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/578">578</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num="0a"/>
        <vers num="0b"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0876" seq="1999-0876" published="2000-01-04" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 4.0 via EMBED tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q185959">Q185959</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0" edition=":mac_os"/>
        <vers num="3.1" edition=":mac_os"/>
        <vers num="4.0" edition="a"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0877" seq="1999-0877" published="1999-10-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243638">Q243638</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-042">MS99-042</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.01" edition="sp1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0878" seq="1999-0878" published="1999-08-22" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/599">599</ref>
    </refs>
    <vuln_soft>
      <prod name="beroftpd" vendor="beroftpd">
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4.2_beta18_vr4"/>
        <vers num="2.4.2_beta18_vr5"/>
        <vers num="2.4.2_beta18_vr6"/>
        <vers num="2.4.2_beta18_vr8"/>
        <vers num="2.4.2_beta18_vr9"/>
        <vers num="2.4.2_beta18_vr10"/>
        <vers num="2.4.2_beta18_vr11"/>
        <vers num="2.4.2_beta18_vr12"/>
        <vers num="2.4.2_beta18_vr13"/>
        <vers num="2.4.2_beta18_vr14"/>
        <vers num="2.4.2_beta18_vr15"/>
        <vers num="2.4.2_vr16"/>
        <vers num="2.4.2_vr17"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0879" seq="1999-0879" published="1999-10-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0880" seq="1999-0880" published="1999-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0881" seq="1999-0881" published="1999-10-26" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/743">743</ref>
    </refs>
    <vuln_soft>
      <prod name="falcon_web_server" vendor="blueface">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0882" seq="1999-0882" published="1999-10-28" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="falcon_web_server" vendor="falcon">
        <vers num="1.0.0.1006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0883" seq="1999-0883" published="1999-10-25" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3380">zeus-remote-root(3380)</ref>
    </refs>
    <vuln_soft>
      <prod name="zeus_web_server" vendor="zeus_technologies">
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0884" seq="1999-0884" published="1999-10-25" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Zeus web server administrative interface uses weak encryption for its passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3833">zeus-weak-password(3833)</ref>
    </refs>
    <vuln_soft>
      <prod name="zeus_web_server" vendor="zeus_technologies">
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0885" seq="1999-0885" published="1999-11-03" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/770">770</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-11-01&amp;msg=01BF261F.928821E0.kerb@fnusa.com">19991103 More Alibaba Web Server problems...</ref>
    </refs>
    <vuln_soft>
      <prod name="alibaba" vendor="computer_software_manufaktur">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0886" seq="1999-0886" published="1999-09-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242294">Q242294</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/645">645</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-041">MS99-041</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0887" seq="1999-0887" published="1999-11-04" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
    </refs>
    <vuln_soft>
      <prod name="ftgate" vendor="floosietek">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0888" seq="1999-0888" published="1999-08-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/585">585</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="7.3.3"/>
        <vers num="7.3.4"/>
      </prod>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.0.5.1"/>
        <vers num="8.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0889" seq="1999-0889" published="1999-07-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="675_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0890" seq="1999-0890" published="1999-09-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.ihtmlmerchant.com/support_patches_feedback.htm" patch="1">http://www.ihtmlmerchant.com/support_patches_feedback.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/694">694</ref>
    </refs>
    <vuln_soft>
      <prod name="ihtml_merchant" vendor="ihtml_merchant">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0891" seq="1999-0891" published="1999-09-01" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242542">Q242542</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-002.shtml">K-002</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/37828">VU#37828</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/674">674</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-040">MS99-040</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0892" seq="1999-0892" published="1999-12-24" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0893" seq="1999-0893" published="1999-10-11" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0894" seq="1999-0894" published="2000-01-04" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0895" seq="1999-0895" published="1999-10-20" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Firewall-1 does not properly restrict access to LDAP attributes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/725">725</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991020150002.21047.qmail@tarjan.mediaways.net">19991020 Checkpoint FireWall-1 V4.0: possible bug in LDAP authentication</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0896" seq="1999-0896" published="1999-11-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://service.real.com/help/faq/servg260.html">http://service.real.com/help/faq/servg260.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/767">767</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver_g2" vendor="realnetworks">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0897" seq="1999-0897" published="1998-09-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90538488231977&amp;w=2">19980908 bug in iChat 3.0 (maybe others)</ref>
    </refs>
    <vuln_soft>
      <prod name="ichat_server" vendor="apple">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0898" seq="1999-0898" published="1999-11-04" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/768">768</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-047">MS99-047</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0899" seq="1999-0899" published="1999-11-04" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/769">769</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-047">MS99-047</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0900" seq="1999-0900" published="1999-10-23" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="rpc.yppasswdd" vendor="linux-nis">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0901" seq="1999-0901" published="1999-10-23" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ypserv allows a local user to modify the GECOS and login shells of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ypserv" vendor="linux-nis">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0902" seq="1999-0902" published="1999-10-23" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ypserv allows local administrators to modify password tables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ypserv" vendor="linux-nis">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0903" seq="1999-0903" published="1999-10-26" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0904" seq="1999-0904" published="1999-11-03" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/771">771</ref>
    </refs>
    <vuln_soft>
      <prod name="bftelnet" vendor="byte_fusion">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0905" seq="1999-0905" published="1999-10-21" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Axent Raptor firewall via malformed zero-length IP options.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/736">736</ref>
    </refs>
    <vuln_soft>
      <prod name="raptor_firewall" vendor="axent">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0906" seq="1999-0906" published="1999-09-23" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/656">656</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0907" seq="1999-0907" published="1999-09-16" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">sccw allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="soundcard_cw" vendor="steven_j._merrifield">
        <vers num="1.1" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0908" seq="1999-0908" published="1999-09-23" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/655">655</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0909" seq="1999-0909" published="1999-09-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238453">Q238453</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/646">646</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-038">MS99-038</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num="0a"/>
        <vers num="0b"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0910" seq="1999-0910" published="1999-09-10" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/625">625</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-035">MS99-035</ref>
    </refs>
    <vuln_soft>
      <prod name="commercial_internet_system" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
      <prod name="site_server_commerce" vendor="microsoft">
        <vers num="3.0" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0911" seq="1999-0911" published="1999-08-27" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/1999/19990210">19990210</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/612">612</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2_pre1"/>
        <vers num="1.2_pre2"/>
        <vers num="1.2_pre3"/>
        <vers num="1.2_pre4"/>
        <vers num="1.2_pre5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0912" seq="1999-0912" published="1999-09-22" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/653">653</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0913" seq="1999-0913" published="1999-08-05" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93383593909438&amp;w=2">19990804 NSW Dragon Fire gets drowned</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/564">564</ref>
    </refs>
    <vuln_soft>
      <prod name="dragon-fire_ids" vendor="network_security_wizards">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0914" seq="1999-0914" published="1999-01-03" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/324">324</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0915" seq="1999-0915" published="1999-10-28" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/746">746</ref>
    </refs>
    <vuln_soft>
      <prod name="url_live" vendor="pacific_software">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0916" seq="1999-0916" published="1999-06-29" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WebTrends software stores account names and passwords in a file which does not have restricted access permissions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="webtrends_enterprise_suite" vendor="webtrends">
        <vers num="v3.5"/>
      </prod>
      <prod name="webtrends_for_firewalls" vendor="webtrends">
        <vers num="v1.2"/>
      </prod>
      <prod name="webtrends_log_analyzer" vendor="webtrends">
        <vers num="v4.51"/>
      </prod>
      <prod name="webtrends_professional_suite" vendor="webtrends">
        <vers num="v3.01"/>
      </prod>
      <prod name="webtrends_security_analyzer" vendor="webtrends">
        <vers num="v2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0917" seq="1999-0917" published="1999-05-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231452">Q231452</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-018">MS99-018</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0918" seq="1999-0918" published="1999-07-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Denial of service in various Windows systems via malformed, fragmented IGMP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238329">Q238329</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/514">514</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-034">MS99-034</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0919" seq="1999-0919" published="1998-05-10" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621" adv="1">19980510 Security Vulnerability in Motorola CableRouters</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2004">motorola-cable-crash(2004)</ref>
    </refs>
    <vuln_soft>
      <prod name="motorola_cablerouter" vendor="motorola">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0920" seq="1999-0920" published="1999-05-26" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/283">283</ref>
    </refs>
    <vuln_soft>
      <prod name="imap" vendor="university_of_washington">
        <vers num="4.4"/>
      </prod>
      <prod name="pop2d" vendor="university_of_washington">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0921" seq="1999-0921" published="1999-04-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/4291.php">bmc-patrol-udp-dos(4291)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1879">1879</ref>
    </refs>
    <vuln_soft>
      <prod name="patrol_agent" vendor="bmc">
        <vers num="3.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0922" seq="1999-0922" published="2001-03-12" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full" adv="1" patch="1">ASB99-02</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0923" seq="1999-0923" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full" adv="1" patch="1">ASB99-02</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0924" seq="1999-0924" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full" adv="1" patch="1">ASB99-02</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1742">coldfusion-syntax-checker(1742)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0925" seq="1999-0925" published="1999-09-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90486243124867&amp;w=2">19980903 Web servers / possible DOS Attack / mime header flooding</ref>
    </refs>
    <vuln_soft>
      <prod name="unitymail" vendor="messagemedia">
        <vers num="2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0926" seq="1999-0926" published="1999-09-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html" adv="1">19990903 Web servers / possible DOS Attack / mime header flooding</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0927" seq="1999-0927" published="1999-05-26" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/279">279</ref>
    </refs>
    <vuln_soft>
      <prod name="ntmail" vendor="gordano">
        <vers num="4.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0928" seq="1999-0928" published="1999-05-23" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/278">278</ref>
    </refs>
    <vuln_soft>
      <prod name="websuite" vendor="smartdesk">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0929" seq="1999-0929" published="1999-06-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="http_server" vendor="novell">
        <vers num="2.51r1"/>
        <vers num="3.1r1"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="4.1"/>
        <vers num="4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0930" seq="1999-0930" published="1998-09-03" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">wwwboard allows a remote attacker to delete message board articles via a malformed argument.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1795">1795</ref>
      <ref source="CONFIRM" url="http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml">http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2344">http-cgi-wwwboard(2344)</ref>
    </refs>
    <vuln_soft>
      <prod name="wwwboard" vendor="matt_wright">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0931" seq="1999-0931" published="1999-09-30" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/734">734</ref>
    </refs>
    <vuln_soft>
      <prod name="statistics_server" vendor="mediahouse_software">
        <vers num="4.28"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0932" seq="1999-0932" published="1999-09-30" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/735">735</ref>
    </refs>
    <vuln_soft>
      <prod name="statistics_server" vendor="mediahouse_software">
        <vers num="4.28"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0933" seq="1999-0933" published="1999-10-01" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/689">689</ref>
    </refs>
    <vuln_soft>
      <prod name="teamtrack" vendor="teamshare">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0934" seq="1999-0934" published="1999-12-15" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2020">2020</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3102">http-cgi-classifieds-read(3102)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-1999-0935" seq="1999-0935" published="1999-12-15" modified="2005-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0936" seq="1999-0936" published="1998-12-03" modified="2005-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0937" seq="1999-0937" published="1998-12-03" modified="2005-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0938" seq="1999-0938" published="1999-06-28" modified="2016-09-16" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Session Initiation Protocol (SIP) messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sdr" vendor="university_college_london">
        <vers num="2.6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0939" seq="1999-0939" published="1999-08-26" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Debian IRC Epic/epic4 client via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/605">605</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
        <vers num="2.2" edition=":pre_potato"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0940" seq="1999-0940" published="1999-09-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="mutt_mail_client" vendor="mutt">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0941" seq="1999-0941" published="1998-07-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mutt mail client allows a remote attacker to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526154&amp;w=2">19980728 mutt x.x</ref>
    </refs>
    <vuln_soft>
      <prod name="mutt" vendor="mutt">
        <vers num="0.95.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0942" seq="1999-0942" published="1999-10-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0943" seq="1999-0943" published="1999-10-15" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/720">720</ref>
    </refs>
    <vuln_soft>
      <prod name="openlink" vendor="openlink">
        <vers num="a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0944" seq="1999-0944" published="1999-10-24" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-0945" seq="1999-0945" published="2001-03-12" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q169174">Q169174</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-080.shtml" adv="1" patch="1">I-080</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise4.php" adv="1" patch="1">19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1223">exchange-dos(1223)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0946" seq="1999-0946" published="1999-11-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/760">760</ref>
    </refs>
    <vuln_soft>
      <prod name="midiplug" vendor="yamaha">
        <vers num="1.1bj"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0947" seq="1999-0947" published="1999-11-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/762">762</ref>
    </refs>
    <vuln_soft>
      <prod name="an-httpd" vendor="an">
        <vers num="1.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0948" seq="1999-0948" published="1999-11-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in uum program for Canna input system allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/757">757</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0949" seq="1999-0949" published="1999-11-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/757">757</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0950" seq="1999-0950" published="1999-10-28" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via	a series of MKD and CWD commands that create nested directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/747">747</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.34"/>
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0951" seq="1999-0951" published="1999-10-22" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/739">739</ref>
    </refs>
    <vuln_soft>
      <prod name="omnihttpd" vendor="omnicron">
        <vers num="1.1"/>
        <vers num="2.4pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0952" seq="1999-0952" published="1999-01-28" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91759216618637&amp;w=2">19990126 Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0953" seq="1999-0953" published="1999-09-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wwwboard" vendor="matt_wright">
        <vers num="2.0_alpha_2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0954" seq="1999-0954" published="1999-09-16" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WWWBoard has a default username and default password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/649">649</ref>
    </refs>
    <vuln_soft>
      <prod name="wwwboard" vendor="matt_wright">
        <vers num="2.0_alpha_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0955" seq="1999-0955" published="1997-09-23" modified="2017-07-18" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0956" seq="1999-0956" published="1997-09-19" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="nextstep" vendor="next">
        <vers num="1.0"/>
        <vers num="1.0a"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0957" seq="1999-0957" published="1997-06-18" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">MajorCool mj_key_cache program allows local users to modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="majorcool" vendor="great_circle_associates">
        <vers num="1.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0958" seq="1999-0958" published="1998-01-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88465708614896&amp;w=2">19980112 Re: hole in sudo for MP-RAS.</ref>
    </refs>
    <vuln_soft>
      <prod name="sudo" vendor="todd_miller">
        <vers num="1.5"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0959" seq="1999-0959" published="1997-02-01" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/469">469</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1634">irix-startmidi-file-creation(1634)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0960" seq="1999-0960" published="1998-03-20" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0961" seq="1999-0961" published="1996-09-21" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167419906&amp;w=2">19960921 Vunerability in HP sysdiag ?</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.04"/>
        <vers num="9.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0962" seq="1999-0962" published="1997-05-14" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045">HPSBUX9701-045</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0963" seq="1999-0963" published="1999-12-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0964" seq="1999-0964" published="2000-01-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0965" seq="1999-0965" published="1997-09-19" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in xterm allows local users to modify arbitrary files via the logging option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="xterm" vendor="x.org">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0966" seq="1999-0966" published="1997-01-27" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0967" seq="1999-0967" published="1997-11-01" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_explorer" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0968" seq="1999-0968" published="1998-12-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11711">19981226 bnc exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1927">1927</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1546">bnc-proxy-bo(1546)</ref>
    </refs>
    <vuln_soft>
      <prod name="bnc_irc" vendor="james_seter">
        <vers num="2.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0969" seq="1999-0969" published="1998-09-29" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q193233">Q193233</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-014">MS98-014</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0970" seq="1999-0970" published="1999-06-05" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14311">19990605 Remote Exploit (Bug) in OmniHTTPd Web Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1808">1808</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2271">omnihttpd-dos(2271)</ref>
    </refs>
    <vuln_soft>
      <prod name="omnihttpd" vendor="omnicron">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0971" seq="1999-0971" published="1997-07-22" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7301">19970722 Security hole in exim 1.62: local root exploit</ref>
    </refs>
    <vuln_soft>
      <prod name="exim" vendor="university_of_cambridge">
        <vers num="1.62" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0972" seq="1999-0972" published="1999-12-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Xshipwars xsw program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/863">863</ref>
    </refs>
    <vuln_soft>
      <prod name="xshipwars" vendor="wolfpack_development">
        <vers num="1.0"/>
        <vers num="1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0973" seq="1999-0973" published="1999-12-07" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/858">858</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0974" seq="1999-0974" published="1999-12-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/190">00190</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/864">864</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0975" seq="1999-0975" published="1999-12-10" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/868">868</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0976" seq="1999-0976" published="1999-12-07" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/857">857</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="8.9.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0977" seq="1999-0977" published="1999-12-10" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/191">00191</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2354">2354</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/866">866</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0978" seq="1999-0978" published="1999-12-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">htdig allows remote attackers to execute commands via filenames with shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/867">867</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0979" seq="1999-0979" published="2000-04-11" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/869">869</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0980" seq="1999-0980" published="2000-05-16" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246045">Q246045</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-055">MS99-055</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0981" seq="1999-0981" published="1999-12-08" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246094">Q246094</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-050">MS99-050</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.01" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0982" seq="1999-0982" published="1999-12-05" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="web-based_enterprise_management" vendor="sun">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0983" seq="1999-0983" published="1999-11-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="whois_lookup" vendor="internic">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0984" seq="1999-0984" published="1999-11-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="matts_whois" vendor="matts_whois">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0985" seq="1999-0985" published="1999-11-09" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cc_whois" vendor="cc">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0986" seq="1999-0986" published="1999-12-08" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/870">870</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0987" seq="1999-0987" published="1999-11-18" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237923">Q237923</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0988" seq="1999-0988" published="1999-12-04" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="2.0"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.1.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0989" seq="1999-0989" published="1999-12-06" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/861">861</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5" edition=":windows_nt_4.0"/>
        <vers num="5.0" edition=":windows_95"/>
        <vers num="5.0" edition=":windows_98"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0990" seq="1999-0990" published="1999-12-05" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="2.0_beta4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0991" seq="1999-0991" published="1999-12-06" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/862">862</ref>
    </refs>
    <vuln_soft>
      <prod name="telnet_server_nt" vendor="goodtech">
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0992" seq="1999-0992" published="2000-01-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9912-107">HPSBUX9912-107</ref>
    </refs>
    <vuln_soft>
      <prod name="vvos" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0993" seq="1999-0993" published="1999-12-13" modified="2017-01-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Modifications to ACLs (Access Control Lists) in Microsoft Exchange  5.5 do not take effect until the directory store cache is refreshed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0994" seq="1999-0994" published="1999-12-16" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248183">Q248183</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/873">873</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-056">MS99-056</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0995" seq="1999-0995" published="1999-12-16" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248185">Q248185</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/875">875</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-057">MS99-057</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0996" seq="1999-0996" published="1999-12-15" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD19991215.html">AD19991215</ref>
    </refs>
    <vuln_soft>
      <prod name="ultraseek_server" vendor="infoseek">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0997" seq="1999-0997" published="1999-12-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-377">DSA-377</ref>
    </refs>
    <vuln_soft>
      <prod name="anonftp" vendor="millenux_gmbh">
        <vers num="2.8.1"/>
      </prod>
      <prod name="wu-ftpd" vendor="university_of_washington">
        <vers num="2.4.2"/>
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0998" seq="1999-0998" published="1999-12-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cisco Cache Engine allows an attacker to replace content in the cache.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cache_engine" vendor="cisco">
        <vers num="2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-0999" seq="1999-0999" published="1999-11-19" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248749">Q248749</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/817">817</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-059">MS99-059</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1000" seq="1999-1000" published="1999-12-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cache_engine" vendor="cisco">
        <vers num="2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1001" seq="1999-1001" published="1999-12-16" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cisco Cache Engine allows a remote attacker to gain access via a null username and password.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cache_engine" vendor="cisco">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1002" seq="1999-1002" published="2000-01-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Navigator uses weak encryption for storing a user's Netscape mail password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94536309217214&amp;w=2">19991216 Reinventing the wheel (aka "Decoding Netscape Mail passwords")</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94570673523998&amp;w=2">19991220 Netscape password scrambling</ref>
      <ref source="MISC" url="http://www.rstcorp.com/news/bad-crypto.html" adv="1">http://www.rstcorp.com/news/bad-crypto.html</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1003" seq="1999-1003" published="1999-12-13" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="warftpd" vendor="jgaa">
        <vers num="1.70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1004" seq="1999-1004" published="1999-12-16" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy">http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/38970">19991217 NAV2000 Email Protection DoS</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39194">19991220 Norton Email Protection Remote Overflow (Addendum)</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1005" seq="1999-1005" published="1999-12-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94571433731824&amp;w=2">19991219 Groupewise Web Interface</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/879">879</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.0.7a"/>
      </prod>
      <prod name="groupwise" vendor="novell">
        <vers num="5.2"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1006" seq="1999-1006" published="1999-12-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94571433731824&amp;w=2">19991219 Groupewise Web Interface</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="5.2"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1007" seq="1999-1007" published="1999-12-13" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94512259331599&amp;w=2">19991213 VDO Live Player 3.02 Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/872">872</ref>
    </refs>
    <vuln_soft>
      <prod name="vdolive_player" vendor="vdonet">
        <vers num="3.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1008" seq="1999-1008" published="2000-05-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xsoldier program allows local users to gain root access via a long argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://marc.info/?l=freebsd-security&amp;m=94531826621620&amp;w=2">http://marc.info/?l=freebsd-security&amp;m=94531826621620&amp;w=2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/871">871</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1009" seq="1999-1009" published="1999-12-12" modified="2008-09-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="go_express_search" vendor="disney">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1010" seq="1999-1010" published="1999-12-14" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94519142415338&amp;w=2">19991214 sshd1 allows unencrypted sessions regardless of server policy</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1011" seq="1999-1011" published="1999-07-19" modified="2018-10-15" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">J-054</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-004">MS98-004</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-025">MS99-025</ref>
      <ref source="BID" url="https://www.securityfocus.com/bid/529">529</ref>
    </refs>
    <vuln_soft>
      <prod name="data_access_components" vendor="microsoft">
        <vers num="1.5"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1012" seq="1999-1012" published="1999-05-04" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13527" adv="1">19990504 AS/400</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/173" adv="1">173</ref>
    </refs>
    <vuln_soft>
      <prod name="domino" vendor="lotus">
        <vers num="4.6.1" edition=":as_400"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1013" seq="1999-1013" published="1999-09-23" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93837026726954&amp;w=2">19990923 named-xfer hole on AIX (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/673" adv="1" patch="1">673</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1.5"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1014" seq="1999-1014" published="1999-09-13" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93727925026476&amp;w=2">19990913 Solaris 2.7 /usr/bin/mail</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93846422810162&amp;w=2">19990927 Working Solaris x86 /usr/bin/mail exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/672" adv="1" patch="1">672</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3297">sun-usrbinmail-local-bo(3297)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1015" seq="1999-1015" published="1998-04-08" modified="2017-11-21" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89200657216213&amp;w=2" adv="1">19980408 AppleShare IP Mail Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/61" adv="1">61</ref>
    </refs>
    <vuln_soft>
      <prod name="appleshare_mail_server" vendor="apple">
        <vers num="5.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1016" seq="1999-1016" published="1999-08-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93578772920970&amp;w=2">19990827 HTML code to crash IE5 and Outlook Express 5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/606" adv="1">606</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num="" edition=":express"/>
      </prod>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
      <prod name="eudora" vendor="qualcomm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1017" seq="1999-1017" published="1999-07-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93316253431588&amp;w=2">19990728 Seattle Labs EMURL Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/544" adv="1" patch="1">544</ref>
    </refs>
    <vuln_soft>
      <prod name="emurl" vendor="seattle_lab_software">
        <vers num="2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1018" seq="1999-1018" published="1999-07-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93312523904591&amp;w=2">19990727 Linux 2.2.10 ipchains Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/543" adv="1" patch="1">543</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
        <vers num="2.2.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1019" seq="1999-1019" published="1999-06-23" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93024398513475&amp;w=2">19990624 Re: Cabletron Spectrum security vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93024398713491&amp;w=2">19990623 Cabletron Spectrum security vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/495" adv="1" patch="1">495</ref>
    </refs>
    <vuln_soft>
      <prod name="spectrum_enterprise_manager" vendor="cabletron">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1020" seq="1999-1020" published="1998-09-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90613355902262&amp;w=2">19980918 NMRC Advisory - Default NDS Rights</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/484" adv="1" patch="1">484</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1364">novell-nds(1364)</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="4.1"/>
        <vers num="4.11" edition="sp5b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1021" seq="1999-1021" published="1992-12-30" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba" patch="1">00117</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html" adv="1" patch="1">CA-1992-15</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/47" adv="1" patch="1">47</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/82">nfs-uid(82)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1022" seq="1999-1022" published="1994-10-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/930" adv="1">19941002</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/464" adv="1" patch="1">464</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2111">sgi-serialports(2111)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="4"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1023" seq="1999-1023" published="1999-06-10" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92904175406756&amp;w=2">19990610 Sun Useradd program expiration date bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/426" adv="1" patch="1">426</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1024" seq="1999-1024" published="2001-11-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92955903802773&amp;w=2">19990616 tcpdump 3.4  bug?</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92963447601748&amp;w=2">19990617 Re: tcpdump 3.4 bug?</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92989907627051&amp;w=2">19990620 Re: tcpdump 3.4 bug? (final)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/313" adv="1" patch="1">313</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1025" seq="1999-1025" published="1998-11-12" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90831127921062&amp;w=2">19981012 Annoying Solaris/CDE/NIS+ bug</ref>
      <ref source="SUNBUG" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F106027&amp;zone_32=411568%2A%20" adv="1" patch="1">4115685</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/294" adv="1" patch="1">294</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1026" seq="1999-1026" published="1996-12-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420343&amp;w=2">19961220 Solaris 2.5 x86 aspppd (semi-exploitable-hole)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/292" adv="1">292</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1027" seq="1999-1027" published="1998-05-07" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925880&amp;w=2">19980507 admintool mode 0777 in Solaris 2.6 HW3/98</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/290" adv="1" patch="1">290</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7296">solaris-admintool-world-writable(7296)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1028" seq="1999-1028" published="1999-05-28" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92807524225090&amp;w=2">19990528 DoS against PC Anywhere</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/2256.php">pcanywhere-dos(2256)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/288" adv="1" patch="1">288</ref>
    </refs>
    <vuln_soft>
      <prod name="pcanywhere" vendor="symantec">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1029" seq="1999-1029" published="1999-05-13" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92663402004280&amp;w=2">19990513 - J.J.F. / Hackers Team warns for SSHD 2.x brute force password hacking</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/277" adv="1" patch="1">277</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2193">ssh2-bruteforce(2193)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh2" vendor="ssh">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1030" seq="1999-1030" published="1999-05-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92713790426690&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92707671717292&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/267" adv="1">267</ref>
    </refs>
    <vuln_soft>
      <prod name="web_page_counter" vendor="behold_software">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1031" seq="1999-1031" published="1999-05-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92713790426690&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92707671717292&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/267">267</ref>
    </refs>
    <vuln_soft>
      <prod name="web_page_counter" vendor="behold_software">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1032" seq="1999-1032" published="1991-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml">B-36</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-11.html" adv="1" patch="1">CA-1991-11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/26" adv="1" patch="1">26</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/584">ultrix-telnet(584)</ref>
    </refs>
    <vuln_soft>
      <prod name="ultrix" vendor="digital">
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1033" seq="1999-1033" published="1999-05-11" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92647407427342&amp;w=2">19990511 Outlook Express Win98 bug</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92663402004275&amp;w=2">19990512 Outlook Express Win98 bug, addition.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/252" adv="1" patch="1">252</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="4.27.3110.1"/>
        <vers num="4.72.3120.0"/>
        <vers num="4.72.3612.1700" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1034" seq="1999-1034" published="1991-05-23" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-08.html" adv="1" patch="1">CA-1991-08</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/b-28.shtml">B-28</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/23" adv="1" patch="1">23</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/583">sysv-login(583)</ref>
    </refs>
    <vuln_soft>
      <prod name="svr4" vendor="att">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1035" seq="1999-1035" published="1999-12-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q192/2/96.asp" adv="1" patch="1">Q192296</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-019">MS98-019</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1823">iis-get-dos(1823)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1036" seq="1999-1036" published="1998-06-26" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
    </refs>
    <vuln_soft>
      <prod name="cops" vendor="cops">
        <vers num="1.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1037" seq="1999-1037" published="1998-06-26" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125986&amp;w=2">19980627 Re: vulnerability in satan, cops &amp; tiger</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7167.php">satan-rexsatan-symlink(7167)</ref>
    </refs>
    <vuln_soft>
      <prod name="satan" vendor="coast">
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1038" seq="1999-1038" published="1998-06-26" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
    </refs>
    <vuln_soft>
      <prod name="tiger" vendor="tamu">
        <vers num="2.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1039" seq="1999-1039" published="1998-05-27" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030" adv="1" patch="1">19980502-01-P3030</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1040" seq="1999-1040" published="1998-04-08" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980501-01-P2869" adv="1" patch="1">19980501-01-P</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-055.shtml" adv="1" patch="1">I-055</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89217373930054&amp;w=2">19980408 SGI O2 ipx security issue</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1041" seq="1999-1041" published="1998-08-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-98.05a">SB-98.05a</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90686250717719&amp;w=2">19980926 Root exploit for SCO OpenServer.</ref>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreen" adv="1" patch="1">VB-98.10</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10420" adv="1">19980827 SCO mscreen vul.</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2v4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1042" seq="1999-1042" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml" adv="1" patch="1">19980813 CRM Temporary File Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="resource_manager" vendor="cisco">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1043" seq="1999-1043" published="1999-12-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-007">MS98-007</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1044" seq="1999-1044" published="1998-05-07" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">I-050</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7431.php">dgux-advfs-softlinks(7431)</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="v4.0"/>
        <vers num="v4.0d" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1045" seq="1999-1045" published="1998-01-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88490880523890&amp;w=2">19980115 [rootshell] Security Bulletin #7</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88492978527261&amp;w=2">19980115 pnserver exploit..</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90338245305236&amp;w=2">19980817 Re: Real Audio Server Version 5 bug?</ref>
      <ref source="MISC" url="http://service.real.com/help/faq/serv501.html" patch="1">http://service.real.com/help/faq/serv501.html</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7297.php">realserver-pnserver-remote-dos(7297)</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver" vendor="realnetworks">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1046" seq="1999-1046" published="1999-03-01" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990302 Multiple IMail Vulnerabilites</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/504">504</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1897">imail-imonitor-overflow(1897)</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1047" seq="1999-1047" published="1999-10-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94026690521279&amp;w=2">19991018 Gauntlet 5.0 BSDI warning</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94036662326185&amp;w=2">19991019 Re: Gauntlet 5.0 BSDI warning</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/3397.php">gauntlet-bsdi-bypass(3397)</ref>
    </refs>
    <vuln_soft>
      <prod name="gauntlet" vendor="bsdi">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1048" seq="1999-1048" published="1998-09-05" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602746719555&amp;w=2">19970821 Buffer overflow in /bin/bash</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/1998/19980909" adv="1" patch="1">19980909 problem with very long pathnames</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10542" adv="1">19980905 BASH buffer overflow, LiNUX x86 exploit</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3414">linux-bash-bo(3414)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="1.3.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1049" seq="1999-1049" published="1999-02-21" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91972006211238&amp;w=2">19990222 Severe Security Hole in ARCserve NT agents (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod name="arcserve_backup" vendor="ca">
        <vers num="6.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1050" seq="1999-1050" published="1999-11-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34600">19991112 FormHandler.cgi</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34939" adv="1">19991116 Re: FormHandler.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/798" adv="1">798</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/799" adv="1">799</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3550">formhandler-cgi-absolute-path(3550)</ref>
    </refs>
    <vuln_soft>
      <prod name="formhandler.cgi" vendor="matt_wright">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1051" seq="1999-1051" published="1999-11-16" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34939" adv="1">19991116 Re: FormHandler.cgi</ref>
    </refs>
    <vuln_soft>
      <prod name="formhandler.cgi" vendor="matt_wright">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1052" seq="1999-1052" published="1999-08-24" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93582550911564&amp;w=2">19990824 Front Page form_results</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1053" seq="1999-1053" published="1999-09-13" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">guestbook.pl cleanses user-inserted SSI commands by removing text between "&lt;!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33674" adv="1">19991105 Guestbook.pl, sloppy SSI handling in Apache? (VD#2)</ref>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/27296" adv="1">19990913 Guestbook perl script (long)</ref>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/27560" adv="1">19990916 Re: Guestbook perl script (error fix)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/776" adv="1" patch="1">776</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.9"/>
      </prod>
      <prod name="matt_wright_guestbook" vendor="matt_wright">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1054" seq="1999-1054" published="1998-09-25" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90675672323825&amp;w=2">19980925 Globetrotter  FlexLM 'lmdown' bogosity</ref>
    </refs>
    <vuln_soft>
      <prod name="flexlm" vendor="globetrotter">
        <vers num="6.0d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1055" seq="1999-1055" published="1999-12-31" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/179">179</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-018">MS98-018</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1737">excel-call(1737)</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="97"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1056" seq="1999-1056" published="1992-12-31" modified="2008-09-09" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1395.  Reason: This candidate is a duplicate of CVE-1999-1395.  Notes: All CVE users should reference CVE-1999-1395 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-1057" seq="1999-1057" published="1990-10-25" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml" adv="1" patch="1">B-04</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-07.html" adv="1" patch="1">CA-1990-07</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7137.php">vms-analyze-processdump-privileges(7137)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/12">12</ref>
    </refs>
    <vuln_soft>
      <prod name="vms" vendor="digital">
        <vers num="5.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1058" seq="1999-1058" published="1999-11-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94329968617085&amp;w=2">19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94337185023159&amp;w=2">19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/818">818</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3543">vermillion-ftp-cwd-overflow(3543)</ref>
    </refs>
    <vuln_soft>
      <prod name="vermillion_ftp_daemon" vendor="arcane_software">
        <vers num="1.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1059" seq="1999-1059" published="1992-02-25" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-04.html" adv="1" patch="1">CA-1992-04</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/3159.php">att-rexecd(3159)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/36">36</ref>
    </refs>
    <vuln_soft>
      <prod name="svr4" vendor="att">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1060" seq="1999-1060" published="1999-02-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91937090211855&amp;w=2">19990217 Tetrix 1.13.16 is Vulnerable</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/340" patch="1">340</ref>
    </refs>
    <vuln_soft>
      <prod name="tetrinet" vendor="tetrix">
        <vers num="1.13.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1061" seq="1999-1061" published="1997-10-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602248518480&amp;w=2">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1876">laserjet-unpassworded(1876)</ref>
    </refs>
    <vuln_soft>
      <prod name="jetdirect" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1062" seq="1999-1062" published="1997-10-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602248518480&amp;w=2">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1876">laserjet-unpassworded(1876)</ref>
    </refs>
    <vuln_soft>
      <prod name="jetdirect" vendor="hp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1063" seq="1999-1063" published="1999-06-01" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14019" adv="1">19990601 whois_raw.cgi problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/304">304</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2251">http-cgi-cdomain(2251)</ref>
    </refs>
    <vuln_soft>
      <prod name="cdomainfree" vendor="cdomain">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1064" seq="1999-1064" published="1999-08-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93555317429630&amp;w=2">19990822</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93582070508957&amp;w=2">19990824 Re: WindowMaker bugs (was sub:none )</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/596">596</ref>
    </refs>
    <vuln_soft>
      <prod name="windowmaker" vendor="windowmaker">
        <vers num="0.60.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1065" seq="1999-1065" published="1999-11-04" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94175465525422&amp;w=2">19991104 Palm Hotsync vulnerable to DoS attack</ref>
    </refs>
    <vuln_soft>
      <prod name="hotsync_manager" vendor="palm_pilot">
        <vers num="3.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1066" seq="1999-1066" published="1999-12-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94589559631535&amp;w=2">19991222 Quake "smurf" - Quake War Utils</ref>
    </refs>
    <vuln_soft>
      <prod name="quake_1_server" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1067" seq="1999-1067" published="1997-05-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420919&amp;w=2">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in webdist.cgi</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1068" seq="1999-1068" published="1997-07-23" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602661419366&amp;w=2">19970723 DoS against Oracle Webserver 2.1 with PL/SQL stored procedures</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="oracle">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1069" seq="1999-1069" published="1997-11-08" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7943" adv="1">19971108 Security bug in iCat Suite version 3.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2126" adv="1">2126</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1620">icat-carbo-server-vuln(1620)</ref>
    </refs>
    <vuln_soft>
      <prod name="electronic_commerce_suite" vendor="icat">
        <vers num="3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1070" seq="1999-1070" published="1998-07-25" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10021" adv="1">19980725 Annex DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="annex" vendor="xylogics">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1071" seq="1999-1071" published="1998-11-30" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91248445931140&amp;w=2">19981130 Security bugs in Excite for Web Servers 1.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1417">excite-world-write(1417)</ref>
    </refs>
    <vuln_soft>
      <prod name="ews" vendor="excite">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1072" seq="1999-1072" published="1998-11-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91248445931140&amp;w=2">19981130 Security bugs in Excite for Web Servers 1.1</ref>
    </refs>
    <vuln_soft>
      <prod name="ews" vendor="excite">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1073" seq="1999-1073" published="1998-11-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91248445931140&amp;w=2">19981130 Security bugs in Excite for Web Servers 1.1</ref>
    </refs>
    <vuln_soft>
      <prod name="ews" vendor="excite">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1074" seq="1999-1074" published="1999-12-31" modified="2008-09-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9138" adv="1" patch="1">19980501 Warning! Webmin Security Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/98">98</ref>
      <ref source="CONFIRM" url="http://www.webmin.com/webmin/changes.html" adv="1">http://www.webmin.com/webmin/changes.html</ref>
    </refs>
    <vuln_soft>
      <prod name="webmin" vendor="webmin">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.21"/>
        <vers num="0.22"/>
        <vers num="0.31"/>
        <vers num="0.41"/>
        <vers num="0.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1075" seq="1999-1075" published="1998-03-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89025820612530&amp;w=2">19980318 AIX 4.1.5 DoS attack (aka "Port 1025 problem")</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1076" seq="1999-1076" published="1999-10-26" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94096348604173&amp;w=2">19991026 Mac OS 9 Idle Lock Bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/745" adv="1">745</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1077" seq="1999-1077" published="1999-11-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94149318124548&amp;w=2">19991101 Re: Mac OS 9 Idle Lock Bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/756" adv="1">756</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1078" seq="1999-1078" published="1999-07-29" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9907&amp;L=ntbugtraq&amp;D=0&amp;P=10370&amp;F=P" adv="1">19990729 WS_FTP Pro 6.0 Weak Password Encryption Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/547">547</ref>
    </refs>
    <vuln_soft>
      <prod name="ws_ftp_pro" vendor="ipswitch">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1079" seq="1999-1079" published="1999-05-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92601792420088&amp;w=2">19990506 AIX Security Fixes Update</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93587956513233&amp;w=2">19990825 AIX security summary</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/439" adv="1" patch="1">439</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/servlet/support/manager?rs=0&amp;rt=0&amp;org=apars&amp;doc=08E0B1A1B85472A1852567C90031BB36">IX80470</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1080" seq="1999-1080" published="1995-05-10" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92633694100270&amp;w=2">19990510 SunOS 5.7 rmmount, no nosuid.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93971288323395&amp;w=2">19991011</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/250">250</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8350">solaris-rmmount-gain-root(8350)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1081" seq="1999-1081" published="2002-01-15" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35">http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35</ref>
      <ref source="MISC" url="http://www.w3.org/Security/Faq/wwwsf8.html#Q87">http://www.w3.org/Security/Faq/wwwsf8.html#Q87</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2054">http-nov-files(2054)</ref>
    </refs>
    <vuln_soft>
      <prod name="web_server" vendor="novell">
        <vers num="2.0" edition=":examples_toolkit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1082" seq="1999-1082" published="1999-10-08" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93941794201059&amp;w=2">19991008 Jana webserver exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/699" adv="1">699</ref>
    </refs>
    <vuln_soft>
      <prod name="jana_web_server" vendor="t._hauck">
        <vers num="1.0"/>
        <vers num="1.40"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1083" seq="1999-1083" published="1999-10-08" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95730430727064&amp;w=2">20000502 Security Bug in Jana HTTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/699">699</ref>
    </refs>
    <vuln_soft>
      <prod name="jana_web_server" vendor="t._hauck">
        <vers num="1.0"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1084" seq="1999-1084" published="1999-12-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=90222453431604&amp;w=2">19980622 Yet another "get yourself admin rights exploit":</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q103/8/61.asp" adv="1" patch="1">Q103861</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-029.shtml" adv="1" patch="1">K-029</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1044" adv="1" patch="1">1044</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-008">MS00-008</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1085" seq="1999-1085" published="1998-06-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125884&amp;w=2">19980612 CORE-SDI-04: SSH insertion attack</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525878&amp;w=2">19980703 UPDATE: SSH insertion attack</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/1126.php">ssh-insert(1126)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/13877">VU#13877</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_shell" vendor="ssh">
        <vers num="1.2.23"/>
        <vers num="1.2.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1086" seq="1999-1086" published="1999-07-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93214475111651&amp;w=2">19990715 NMRC Advisory: Netware 5 Client Hijacking</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/528" adv="1" patch="1">528</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="4.1"/>
        <vers num="4.11" edition="sp5b"/>
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1087" seq="1999-1087" published="1999-12-31" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q168/6/17.asp" adv="1" patch="1">Q168617</ref>
      <ref source="CONFIRM" url="http://www.microsoft.com/Windows/Ie/security/dotless.asp">http://www.microsoft.com/Windows/Ie/security/dotless.asp</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-016">MS98-016</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2209">ie-dotless(2209)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1088" seq="1999-1088" published="1997-01-09" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" adv="1" patch="1">H-21</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2012">hp-chsh(2012)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.02" prev="1"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1089" seq="1999-1089" published="1996-12-13" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-16.shtml" adv="1" patch="1">H-16</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" adv="1" patch="1">H-21</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420285&amp;w=2">19961209 the HP Bug of the Week!</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2008">hp-chfn(2008)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10"/>
        <vers num="10.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1090" seq="1999-1090" published="1991-09-10" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-15.html" adv="1" patch="1">CA-1991-15</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1844">ftp-ncsa(1844)</ref>
    </refs>
    <vuln_soft>
      <prod name="telnet" vendor="ncsa">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1091" seq="1999-1091" published="2002-01-15" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167419835&amp;w=2">19960903 [BUG] Vulnerability in TIN</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167419839&amp;w=2">19960903 Re: BoS:      [BUG] Vulnerability in TIN</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420726&amp;w=2">19970329 symlink bug in tin/rtin</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/431">tin-tmpfile(431)</ref>
    </refs>
    <vuln_soft>
      <prod name="rtin" vendor="rtin">
        <vers num=""/>
      </prod>
      <prod name="tin" vendor="tin">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1092" seq="1999-1092" published="1999-11-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94286179032648&amp;w=2">19991117 default permissions for tin</ref>
    </refs>
    <vuln_soft>
      <prod name="tin" vendor="iain_lea">
        <vers num="1.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1093" seq="1999-1093" published="1999-12-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q191/2/00.asp">Q191200</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/1276.php">java-script-patch(1276)</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-011">MS98-011</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1" prev="1" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1094" seq="1999-1094" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88480839506155&amp;w=2">19980114 L0pht Advisory MSIE4.0(1)</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp" adv="1" patch="1">Q176697</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/917">iemk-bug(917)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1095" seq="1999-1095" published="1997-10-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87619953510834&amp;w=2">19971006 KSR[T] Advisory #3: updatedb / crontabs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88886870129518&amp;w=2">19980302 overwrite any file with updatedb</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88890116304676&amp;w=2">19980303 updatedb stuff</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.1"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1096" seq="1999-1096" published="1998-05-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925954&amp;w=2">19980516 kde exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925959&amp;w=2">19980517 simple kde exploit fix</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1644">kde-klock-home-bo(1644)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1097" seq="1999-1097" published="1999-05-04" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92586457816446&amp;w=2">19990504 Microsoft Netmeeting Hole</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2187">netmeeting-clipboard(2187)</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num="2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1098" seq="1999-1098" published="1995-03-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1995-03.html" adv="1" patch="1">CA-1995-03</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/f-12.shtml" adv="1" patch="1">F-12</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/516.php">bsd-telnet(516)</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd" vendor="bsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1099" seq="1999-1099" published="1996-11-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420184&amp;w=2">19961122 L0pht Kerberos Advisory</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/65">kerberos-user-grab(65)</ref>
    </refs>
    <vuln_soft>
      <prod name="kth_kerberos" vendor="kth">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1100" seq="1999-1100" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-056.shtml">I-056</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixkey-pub.shtml" adv="1" patch="1">19980616 PIX Private Link Key Processing and Cryptography Issues</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1579">cisco-pix-parse-error(1579)</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_private_link" vendor="cisco">
        <vers num="4.1(6)" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1101" seq="1999-1101" published="1999-02-19" modified="2008-09-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12618">19990219 Yet Another password storing problem (was: Re: Possible Netscape Crypto Security Flaw)</ref>
    </refs>
    <vuln_soft>
      <prod name="lydia" vendor="kab_software">
        <vers num="3.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1102" seq="1999-1102" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-25.shtml" adv="1" patch="1">E-25a</ref>
      <ref source="BUGTRAQ" url="http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm">19940307 8lgm Advisory Releases</ref>
      <ref source="MISC" url="http://www.phreak.org/archives/security/8lgm/8lgm.lpr" adv="1">http://www.phreak.org/archives/security/8lgm/8lgm.lpr</ref>
    </refs>
    <vuln_soft>
      <prod name="a_ux" vendor="apple">
        <vers num="2.0.1"/>
      </prod>
      <prod name="bsd" vendor="bsd">
        <vers num="4.3"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="5.2" prev="1"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1103" seq="1999-1103" published="1996-04-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml" adv="1" patch="1">G-18</ref>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.05.dec" adv="1" patch="1">VB-96.05</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7138.php">osf-dxconsole-gain-privileges(7138)</ref>
      <ref source="MISC" url="http://www.tao.ca/fire/bos/0209.html">http://www.tao.ca/fire/bos/0209.html</ref>
    </refs>
    <vuln_soft>
      <prod name="osf_1" vendor="digital">
        <vers num="3.2c" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1104" seq="1999-1104" published="1999-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167418931&amp;w=2">19951205 Cracked: WINDOWS.PWL</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88536273725787&amp;w=2">19980120 How to recover private keys for various Microsoft products</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=88540877601866&amp;w=2">19980121 How to recover private keys for various Microsoft products</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q140/5/57.asp">Q140557</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/71.php">win95-nbsmbpwl(71)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1105" seq="1999-1105" published="1999-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7231.php">win95-netware-hidden-share(7231)</ref>
      <ref source="MISC" url="http://www.net-security.sk/bugs/NT/netware1.html" adv="1" patch="1">http://www.net-security.sk/bugs/NT/netware1.html</ref>
      <ref source="CONFIRM" url="http://www.zdnet.com/eweek/reviews/1016/tr42bug.html" adv="1" patch="1">http://www.zdnet.com/eweek/reviews/1016/tr42bug.html</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1106" seq="1999-1106" published="1998-04-29" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9121" adv="1">19980429 Security hole in kppp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/92">92</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1643">kde-kppp-account-bo(1643)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1107" seq="1999-1107" published="1998-11-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1650">kde-kppp-path-bo(1650)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1108" seq="1999-1108" published="1998-11-18" modified="2008-09-09" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1107.  Reason: This candidate is a duplicate of CVE-1999-1107.  Notes: All CVE users should reference CVE-1999-1107 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-1109" seq="1999-1109" published="1999-12-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94632241202626&amp;w=2">19991222 Re: procmail / Sendmail - five bugs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94780566911948&amp;w=2">20000113 Re: procmail / Sendmail - five bugs</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7760.php">sendmail-etrn-dos(7760)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/904">904</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.10.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1110" seq="1999-1110" published="1999-11-14" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34675" adv="1" patch="1">19991114 IE 5.0 and Windows Media Player ActiveX object allow checking the existence of local files and directories</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/793" adv="1" patch="1">793</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1111" seq="1999-1111" published="1999-11-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94218618329838&amp;w=2">19911109 ImmuniX OS Security Alert: StackGuard 1.21 Released</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/786">786</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3524">immunix-stackguard-bo(3524)</ref>
    </refs>
    <vuln_soft>
      <prod name="stackguard" vendor="immunix">
        <vers num="1.21" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1112" seq="1999-1112" published="1999-11-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://stud4.tuwien.ac.at/~e9227474/main2.html" adv="1">http://stud4.tuwien.ac.at/~e9227474/main2.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34066" adv="1">19991109 Irfan view 3.07 buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/781" adv="1" patch="1">781</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3549">irfan-view32-bo(3549)</ref>
    </refs>
    <vuln_soft>
      <prod name="irfanview" vendor="irfanview">
        <vers num="3.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1113" seq="1999-1113" published="1998-04-14" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89258194718577&amp;w=2">19980414 MacOS based buffer overflows...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/75">75</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_mail_server" vendor="eudora">
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.01" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1114" seq="1999-1114" published="1998-04-08" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.17.suid_exec.vul">AA-96.17</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980405-01-I" adv="1" patch="1">19980405-01-I</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-15a.shtml" adv="1" patch="1">H-15A</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/467" adv="1" patch="1">467</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2100">ksh-suid_exec(2100)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1115" seq="1999-1115" published="1990-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-04.html" adv="1" patch="1">CA-1990-04</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/a-30.shtml">A-30</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6721.php">apollo-suidexec-unauthorized-access(6721)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7">7</ref>
    </refs>
    <vuln_soft>
      <prod name="apollo_domain_os" vendor="hp">
        <vers num="sr10.2"/>
        <vers num="sr10.3" prev="1" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1116" seq="1999-1116" published="1997-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX" adv="1" patch="1">19970503-01-PX</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/462" adv="1" patch="1">462</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2108">sgi-runpriv(2108)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1117" seq="1999-1117" published="1999-12-31" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml" adv="1" patch="1">H-13</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420195&amp;w=2">19961125 lquerypv fix</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420196&amp;w=2">19961125 AIX lquerypv</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;w=2&amp;r=1&amp;s=lquerypv&amp;q=b">19961124</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/455">455</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1752">ibm-lquerypv(1752)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1118" seq="1999-1118" published="1998-03-11" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/165&amp;type=0&amp;nav=sec.sba" adv="1" patch="1">00165</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/433" adv="1" patch="1">433</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/817">sun-ndd(817)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1119" seq="1999-1119" published="1992-04-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-09.html" adv="1" patch="1">CA-1992-09</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/41">41</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3154">aix-anon-ftp(3154)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="" edition=":32-bit"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1120" seq="1999-1120" published="1997-01-04" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX">19961203-01-PX</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX" adv="1" patch="1">19961203-02-PX</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420403&amp;w=2">19970104 Irix: netprint story</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/395" adv="1" patch="1">395</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2107">sgi-netprint(2107)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1121" seq="1999-1121" published="1992-03-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-06.html" adv="1" patch="1">CA-1992-06</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/38">38</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/554">ibm-uucp(554)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1122" seq="1999-1122" published="1989-07-26" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1989-02.html" adv="1" patch="1">CA-1989-02</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/ciac-08.shtml">CIAC-08</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3">3</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6695">sun-restore-gain-privileges(6695)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1123" seq="1999-1123" published="1991-05-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/107&amp;type=0&amp;nav=sec.sba" adv="1" patch="1">00107</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-07.html" adv="1" patch="1">CA-1991-07</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/21">21</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/22">22</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/582">sun-sourcetapes(582)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.0.3"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1124" seq="1999-1124" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://packetstorm.securify.com/mag/phrack/phrack54/P54-08">http://packetstorm.securify.com/mag/phrack/phrack54/P54-08</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="allaire">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1125" seq="1999-1125" published="1997-09-19" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602880019796&amp;w=2">19970919 Instresting practises of Oracle [Oracle Webserver]</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="oracle">
        <vers num="1.0"/>
        <vers num="2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1126" seq="1999-1126" published="1999-12-31" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-086.shtml" adv="1" patch="1">I-086</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml" adv="1" patch="1">19980813 CRM Temporary File Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1575">cisco-crm-file-vuln(1575)</ref>
    </refs>
    <vuln_soft>
      <prod name="resource_manager" vendor="cisco">
        <vers num="1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1127" seq="1999-1127" published="1999-12-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q195/7/33.asp" adv="1" patch="1">Q195733</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/523.php">nt-spoolss(523)</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-017">MS98-017</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1128" seq="1999-1128" published="1997-03-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://members.tripod.com/~unibyte/iebug3.htm">http://members.tripod.com/~unibyte/iebug3.htm</ref>
      <ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html">http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1129" seq="1999-1129" published="1999-09-01" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm" adv="1">http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/26008" adv="1" patch="1">19990901 VLAN Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/615" adv="1" patch="1">615</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3294">cisco-catalyst-vlan-frames(3294)</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_2900_vlan" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="11.2(8)sa5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1130" seq="1999-1130" published="1999-07-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93346448121208&amp;w=2">19990730 Netscape Enterprise Server yeilds source of JHTML</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93337389603117&amp;w=2">19990730 Netscape Enterprise Server yeilds source of JHTML</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/559">559</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.5.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1131" seq="1999-1131" published="1997-10-24" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX" adv="1" patch="1">19980601-01-PX</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-060.shtml" adv="1" patch="1">I-060</ref>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.12.opengroup" adv="1" patch="1">VB-97.12</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1123">sgi-osf-dce-dos(1123)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1132" seq="1999-1132" published="1999-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90763508011966&amp;w=2">19981005 NMRC Advisory - Lame NT Token Ring DoS</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=90760603030452&amp;w=2">19981002 NMRC Advisory - Lame NT Token Ring DoS</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q179/1/57.asp" adv="1" patch="1">Q179157</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/1399.php">token-ring-dos(1399)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1133" seq="1999-1133" published="1997-09-01" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=87602880019776&amp;w=2">HPSBUX9709-069</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/499">hp-vue-dt(499)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1134" seq="1999-1134" published="1994-05-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-23.shtml" adv="1" patch="1">E-23</ref>
      <ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/008">HPSBUX9404-008</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/2284.php">hp-vue(2284)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1135" seq="1999-1135" published="1994-04-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/027">HPSBUX9504-027</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2284">hp-vue(2284)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1136" seq="1999-1136" published="1998-07-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://cert.ip-plus.net/bulletin-archive/msg00040.html" adv="1" patch="1">HPSBMP9807-005</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526177&amp;w=2">19980729 HP-UX Predictive &amp; Netscape SSL Vulnerabilities</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-081.shtml" adv="1" patch="1">I-081</ref>
      <ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9807-081.html">HPSBUX9807-081</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1413">mpeix-predictive(1413)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00" prev="1"/>
      </prod>
      <prod name="mpe_ix" vendor="hp">
        <vers num="5.0"/>
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1137" seq="1999-1137" published="1993-10-01" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba" adv="1" patch="1">00122</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/e-01.shtml" adv="1" patch="1">E-01</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/549">sun-audio(549)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
        <vers num="5.0"/>
        <vers num="5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1138" seq="1999-1138" published="1993-09-17" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-13.html">CA-1993-13</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/546">sco-homedir(546)</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
      <prod name="open_desktop_lite" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="system_v386_3.2_operating_system"/>
        <vers num="system_v386_3.2_operating_system_2.0"/>
        <vers num="system_v386_3.2_operating_system_4.0"/>
        <vers num="system_v386_3.2_operating_system_4.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1139" seq="1999-1139" published="1997-09-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602880019745&amp;w=2">19970901 HP UX Bug :)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html" adv="1" patch="1">19980121 HP-UX CUE, CUD and LAND vulnerabilities</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-027b.shtml">I-027B</ref>
      <ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html" adv="1" patch="1">HPSBUX9801-074</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/2007.php">hp-cue(2007)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1140" seq="1999-1140" published="1997-12-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88209041500913&amp;w=2">19971214 buffer overflows in cracklib?!</ref>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.16.CrackLib" adv="1" patch="1">VB-97.16</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1539">cracklib-bo(1539)</ref>
    </refs>
    <vuln_soft>
      <prod name="cracklib" vendor="alec_muffet">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1141" seq="1999-1141" published="1997-05-15" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420981&amp;w=2">19970515 MicroSolved finds hole in Ascom Timeplex Router Security</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1824">ascom-timeplex-debug(1824)</ref>
    </refs>
    <vuln_soft>
      <prod name="timeplex_routers" vendor="ascom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1142" seq="1999-1142" published="1992-05-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SunOS 4.1.2 and earlier allows local users to gain privileges via "LD_*" environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116">00116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-11.html" adv="1" patch="1">CA-1992-11</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3152">sun-env(3152)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1143" seq="1999-1143" published="1997-05-28" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX">19970504-01-PX</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-65.shtml" adv="1" patch="1">H-065</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2109">sgi-rld(2109)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1144" seq="1999-1144" published="1997-01-30" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html" adv="1" patch="1">HPSBUX9701-051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2056">hp-mpower(2056)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1145" seq="1999-1145" published="1997-01-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml" adv="1" patch="1">H-21</ref>
      <ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=1514">HPSBUX9701-044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2059">hp-glanceplus(2059)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1146" seq="1999-1146" published="1994-05-04" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/advisories/1555" adv="1" patch="1">HPSBUX9405-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2060">hp-glanceplus-gpm(2060)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="8"/>
        <vers num="9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1147" seq="1999-1147" published="1998-12-04" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91273739726314&amp;w=2">19981204 [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1430">pcm-dos-execute(1430)</ref>
    </refs>
    <vuln_soft>
      <prod name="policy_compliance_manager" vendor="platinum">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1148" seq="1999-1148" published="1999-12-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP" adv="1" patch="1">Q189262</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-006">MS98-006</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1215">iis-passive-ftp(1215)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1149" seq="1999-1149" published="1998-07-16" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CSM Proxy 4.1 allows remote attackers to cause a denial of service (crash) via a long string to the FTP port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525993&amp;w=2">19980716 S.A.F.E.R. Security Bulletin 980708.DOS.1.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1422">csm-proxy-dos(1422)</ref>
    </refs>
    <vuln_soft>
      <prod name="csm_proxy" vendor="computer_software_manufaktur">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1150" seq="1999-1150" published="1998-06-30" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9723" adv="1">19980630 Livingston Portmaster - ISN generation is loosy!</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1882">portmaster-fixed-isn(1882)</ref>
    </refs>
    <vuln_soft>
      <prod name="portmaster" vendor="livingston_portmaster">
        <vers num="initial"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1151" seq="1999-1151" published="1998-06-03" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90296493106214&amp;w=2">19980603 Compaq/Microcom 6000 DoS + more</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2089">microcom-dos(2089)</ref>
    </refs>
    <vuln_soft>
      <prod name="microcom_6000_access_integrator" vendor="compaq_microcom">
        <vers num="initial"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1152" seq="1999-1152" published="1998-06-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90296493106214&amp;w=2">19980603 Compaq/Microcom 6000 DoS + more</ref>
    </refs>
    <vuln_soft>
      <prod name="microcom_6000_access_integrator" vendor="compaq_microcom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1153" seq="1999-1153" published="1998-11-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1400">cgi-perl-mail-programs(1400)</ref>
    </refs>
    <vuln_soft>
      <prod name="hamcards_postcard_cgi" vendor="hamcards_postcard_cgi">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1154" seq="1999-1154" published="1998-11-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lakeweb.com/scripts/" adv="1">http://lakeweb.com/scripts/</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11175" adv="1" patch="1">19981109 Several new CGI vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1400">cgi-perl-mail-programs(1400)</ref>
    </refs>
    <vuln_soft>
      <prod name="filemail_cgi_script" vendor="lakeweb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1155" seq="1999-1155" published="1998-11-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lakeweb.com/scripts/" adv="1">http://lakeweb.com/scripts/</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11175" adv="1" patch="1">19981109 Several new CGI vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1400">cgi-perl-mail-programs(1400)</ref>
    </refs>
    <vuln_soft>
      <prod name="mail_list_cgi_script" vendor="lakeweb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1156" seq="1999-1156" published="1999-05-17" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2254">bisonware-port-crash(2254)</ref>
    </refs>
    <vuln_soft>
      <prod name="bisonware_ftp_server" vendor="bisonware">
        <vers num="4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1157" seq="1999-1157" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP" adv="1" patch="1">Q192774</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3894">tcpipsys-icmp-dos(3894)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1158" seq="1999-1158" published="1997-05-13" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.09.Solaris.passwd.buffer.overrun.vul">AA-97.09</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/139&amp;type=0&amp;nav=sec.sba" adv="1" patch="1">00139</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1159" seq="1999-1159" published="1998-12-29" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91495920911490&amp;w=2">19981229 ssh2 security problem (and patch) (fwd)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1471">ssh-privileged-port-forward(1471)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh2" vendor="ssh">
        <vers num="2.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1160" seq="1999-1160" published="1997-02-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-33.shtml" adv="1" patch="1">H-33</ref>
      <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=87602167420581&amp;w=2">HPSBUX9702-055</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7437.php">hp-ftpd-kftpd(7437)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1161" seq="1999-1161" published="1996-11-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml" adv="1" patch="1">H-32</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420102&amp;w=2">19961103 Re: Untitled</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420103&amp;w=2">19961104 ppl bugs</ref>
      <ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html" adv="1" patch="1">HPSBUX9704-057</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7438.php">hp-ppl(7438)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
        <vers num="10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1162" seq="1999-1162" published="1993-05-24" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-08.html" adv="1" patch="1">CA-1993-08</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/542.php">sco-passwd-deny(542)</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num="1.1"/>
        <vers num="2.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1163" seq="1999-1163" published="1999-11-24" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://marc.info/?l=bugtraq&amp;m=94347039929958&amp;w=2">HPSBUX9911-105</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7439.php">hp-ssp(7439)</ref>
    </refs>
    <vuln_soft>
      <prod name="9000" vendor="hp">
        <vers num="800"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1164" seq="1999-1164" published="1999-06-25" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93041631215856&amp;w=2">19990625 Outlook denial of service</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="97"/>
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1165" seq="1999-1165" published="1999-07-21" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93268249021561&amp;w=2">19990721 old gnu finger bugs</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/2478" adv="1">19950317 GNU finger 1.37 executes ~/.fingerrc with gid root</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/535" adv="1" patch="1">535</ref>
    </refs>
    <vuln_soft>
      <prod name="fingerd" vendor="gnu">
        <vers num="1.37"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1166" seq="1999-1166" published="1999-07-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/18156" adv="1" patch="1">19990711 Linux 2.0.37 segment limit bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/523" adv="1" patch="1">523</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0.37"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1167" seq="1999-1167" published="1999-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7252.php">thirdvoice-cross-site-scripting(7252)</ref>
      <ref source="MISC" url="http://www.wired.com/news/technology/0,1282,20636,00.html" adv="1">http://www.wired.com/news/technology/0,1282,20636,00.html</ref>
      <ref source="CONFIRM" url="http://www.wired.com/news/technology/0,1282,20677,00.html" adv="1">http://www.wired.com/news/technology/0,1282,20677,00.html</ref>
    </refs>
    <vuln_soft>
      <prod name="third_voice_web" vendor="third_voice">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1168" seq="1999-1168" published="1999-02-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12640">19990220 ISS install.iss security hole</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_security_scanner" vendor="iss">
        <vers num="5.3" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1169" seq="1999-1169" published="1999-02-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12284">19990204 NOBO denial of service</ref>
    </refs>
    <vuln_soft>
      <prod name="nobo" vendor="flavio_veloso">
        <vers num="1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1170" seq="1999-1170" published="1999-01-02" modified="2019-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91816507920544&amp;w=2">19990204 WS FTP Server Remote DoS Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/218">218</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0"/>
      </prod>
      <prod name="ipswitch_ws_ftp_server" vendor="progress">
        <vers num="1.0.1.e"/>
        <vers num="1.0.2.e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1171" seq="1999-1171" published="1999-02-02" modified="2019-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91816507920544&amp;w=2">19990204 WS FTP Server Remote DoS Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/218">218</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0"/>
      </prod>
      <prod name="ipswitch_ws_ftp_server" vendor="progress">
        <vers num="1.0.1.e"/>
        <vers num="1.0.2.e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1172" seq="1999-1172" published="1999-01-14" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11947">19990114 security hole in Maximizer</ref>
    </refs>
    <vuln_soft>
      <prod name="maximizer_enterprise" vendor="maximizer">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1173" seq="1999-1173" published="1998-12-18" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91404045014047&amp;w=2">19981218 wordperfect 8 for linux security</ref>
    </refs>
    <vuln_soft>
      <prod name="wordperfect" vendor="corel">
        <vers num="8" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1174" seq="1999-1174" published="2001-12-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.counterpane.com/crypto-gram-9812.html#doghouse">http://www.counterpane.com/crypto-gram-9812.html#doghouse</ref>
    </refs>
    <vuln_soft>
      <prod name="zip_100_mb_drive" vendor="iomega">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1175" seq="1999-1175" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-054.shtml" adv="1" patch="1">I-054</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/wccpauth-pub.shtml" adv="1" patch="1">19980513 Cisco Web Cache Control Protocol Router Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1577">cisco-wccp-vuln(1577)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1176" seq="1999-1176" published="1998-01-10" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cidentd ident daemon allows local users to gain root privileges via a long line in the .authlie script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88466930416716&amp;w=2">19980110 Cidentd</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90554230925545&amp;w=2">19980911 Re: security problems with jidentd</ref>
    </refs>
    <vuln_soft>
      <prod name="cidentd" vendor="aaron_ledbetter">
        <vers num=""/>
      </prod>
      <prod name="jidentd" vendor="jidentd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1177" seq="1999-1177" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.w3.org/Security/Faq/wwwsf4.html">http://www.w3.org/Security/Faq/wwwsf4.html</ref>
      <ref source="CONFIRM" url="http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish" adv="1" patch="1">http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2055">http-cgi-nphpublish(2055)</ref>
    </refs>
    <vuln_soft>
      <prod name="nph-publish" vendor="lincoln_d._stein">
        <vers num="1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1178" seq="1999-1178" published="1998-06-10" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9505" adv="1" patch="1">19980610 Sambar Server Beta BUG..</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3223">sambar-dump-env(3223)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="4.1" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1179" seq="1999-1179" published="1998-05-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9330" adv="1" patch="1">19980515 May SysAdmin man.sh security hole</ref>
    </refs>
    <vuln_soft>
      <prod name="man.sh" vendor="sysadmin_magazine">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1180" seq="1999-1180" published="1999-02-16" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.</descript>
    </desc>
    <sols>
      <sol source="nvd">O'Reilly has corrected this issue in WebSite Professional 2.5, which is now available from:  http://website.oreilly.com</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="website" vendor="oreilly">
        <vers num="1.1e"/>
      </prod>
      <prod name="website_pro" vendor="oreilly">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1181" seq="1999-1181" published="1998-09-29" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980901-01-PX" adv="1" patch="1">19980901-01-PX</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-003.shtml" adv="1" patch="1">J-003</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7441.php">irix-register(7441)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1182" seq="1999-1182" published="1997-07-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602661419318&amp;w=2">19970717 KSR[T] Advisory #2: ld.so</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602661419351&amp;w=2">19970722 ld.so vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88661732807795&amp;w=2">19980204 An old ld-linux.so hole</ref>
    </refs>
    <vuln_soft>
      <prod name="dld" vendor="delix">
        <vers num="5.2"/>
      </prod>
      <prod name="openlinux_lite" vendor="caldera">
        <vers num="1.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
      <prod name="lst_power_linux" vendor="lst">
        <vers num="2.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1183" seq="1999-1183" published="1998-04-02" modified="2013-08-21" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980403-01-PX" adv="1" patch="1">19980403-01-PX</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980403-02-PX" adv="1" patch="1">19980403-02-PX</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/809.php">sgi-mailcap(809)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1184" seq="1999-1184" published="1997-05-13" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420967&amp;w=2">19970513</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420970&amp;w=2">19970514 Re: ELM overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="elm" vendor="elm_development_group">
        <vers num="2.3"/>
        <vers num="2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1185" seq="1999-1185" published="1998-10-06" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90686250717719&amp;w=2">19980926 Root exploit for SCO OpenServer.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1379">sco-openserver-mscreen-bo(1379)</ref>
    </refs>
    <vuln_soft>
      <prod name="cmw" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="internet_faststart" vendor="sco">
        <vers num="all_versions"/>
      </prod>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="3.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="openserver_enterprise_system" vendor="sco">
        <vers num="5.0.4p"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1186" seq="1999-1186" published="1996-01-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167418966&amp;w=2">19960102 rxvt security hole</ref>
    </refs>
    <vuln_soft>
      <prod name="rxvt" vendor="rxvt">
        <vers num=""/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="2.1"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1187" seq="1999-1187" published="1996-08-26" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167419803&amp;w=2">19960826 [BUG] Vulnerability in PINE</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/416">pine-tmpfile(416)</ref>
    </refs>
    <vuln_soft>
      <prod name="pine" vendor="university_of_washington">
        <vers num="3.94" prev="1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.0"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1188" seq="1999-1188" published="1998-12-27" modified="2019-10-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91479159617803&amp;w=2">19981227 mysql: mysqld creates world readable logs..</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1568">mysql-readable-log-files(1568)</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1189" seq="1999-1189" published="1999-11-24" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36306" adv="1">19991124 Netscape Communicator 4.7 - Navigator Overflows</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36608" adv="1">19991127 Netscape Communicator 4.7 - Navigator Overflows</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/822" adv="1" patch="1">822</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7884">netscape-long-argument-bo(7884)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.7"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1190" seq="1999-1190" published="1999-11-15" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html" adv="1">http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/801" adv="1" patch="1">801</ref>
    </refs>
    <vuln_soft>
      <prod name="emailclub" vendor="admiral_systems">
        <vers num="1.0.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1191" seq="1999-1191" published="1997-05-19" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul" adv="1" patch="1">AA-97.18</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167418335&amp;w=2">19970519 Re: Finally, most of an exploit for Solaris 2.5.1's ps.</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/144" adv="1" patch="1">00144</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7442.php">solaris-chkey-bo(7442)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/207" adv="1" patch="1">207</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1192" seq="1999-1192" published="1997-06-24" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/143" adv="1" patch="1">00143</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7444.php">solaris-eeprom-bo(7444)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/206" adv="1" patch="1">206</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1193" seq="1999-1193" published="1991-05-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-06.html" adv="1" patch="1">CA-1991-06</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/20">20</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/581">next-me(581)</ref>
    </refs>
    <vuln_soft>
      <prod name="next" vendor="next">
        <vers num="2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1194" seq="1999-1194" published="1991-05-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-05.html" adv="1" patch="1">CA-1991-05</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/17">17</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/577">dec-chroot(577)</ref>
    </refs>
    <vuln_soft>
      <prod name="ultrix" vendor="digital">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1195" seq="1999-1195" published="1999-05-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92588169005196&amp;w=2">19990505 NAI AntiVirus Update Problem</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92587579032534&amp;w=2">19990505 NAI AntiVirus Update Problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/169">169</ref>
    </refs>
    <vuln_soft>
      <prod name="virusscan" vendor="network_associates">
        <vers num="4.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1196" seq="1999-1196" published="1999-04-07" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to a non-vulnerable version of Exceed (Hummingbird Exceed 6.0.1 Hummingbird Exceed 6.0.2 Hummingbird Exceed 6.1)</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13451">19990427 NT/Exceed D.O.S.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/158">158</ref>
    </refs>
    <vuln_soft>
      <prod name="exceed" vendor="hummingbird">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1197" seq="1999-1197" published="1990-12-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-12.html" adv="1" patch="1">CA-1990-12</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7140.php">sunos-tioccons-console-redirection(7140)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/14">14</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1198" seq="1999-1198" published="1990-10-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" adv="1" patch="1">B-01</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html" adv="1" patch="1">CA-1990-06</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7141.php">nextstep-builddisk-root-access(7141)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/11">11</ref>
    </refs>
    <vuln_soft>
      <prod name="next" vendor="next">
        <vers num="2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1199" seq="1999-1199" published="1998-08-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90252779826784&amp;w=2">19980807 YA Apache DoS attack</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90276683825862&amp;w=2">19980808 Debian Apache Security Update</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90280517007869&amp;w=2">19980811 Apache 'sioux' DOS fix for TurboLinux</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90286768232093&amp;w=2">19980810 Apache DoS Attack</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#apache">http://www.redhat.com/support/errata/rh51-errata-general.html#apache</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1200" seq="1999-1200" published="1998-07-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vintra SMTP MailServer allows remote attackers to cause a denial of service via a malformed "EXPN *@" command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=90222454131610&amp;w=2">19980720 DOS in Vintra systems Mailserver software.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1617">vintra-mail-dos(1617)</ref>
    </refs>
    <vuln_soft>
      <prod name="smtp_mailserver" vendor="vintra_systems">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1201" seq="1999-1201" published="1999-02-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91849617221319&amp;w=2">19990206 New Windows 9x Bug:  TCP Chorusing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/225">225</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7542">win-multiple-ip-dos(7542)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1202" seq="1999-1202" published="1998-07-03" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">StarTech (1) POP3 proxy server and (2) telnet server allows remote attackers to cause a denial of service via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525873&amp;w=2">19980703 Windows95 Proxy DoS Vulnerabilites</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2088">startech-pop3-overflow(2088)</ref>
    </refs>
    <vuln_soft>
      <prod name="pop3_proxy_server" vendor="startech">
        <vers num=""/>
      </prod>
      <prod name="telnet_server" vendor="startech">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1203" seq="1999-1203" published="1999-02-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91868964203769&amp;w=2">19990210 Security problems in ISDN equipment authentication</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91888117502765&amp;w=2">19990212 PPP/ISDN multilink security issue - summary</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7498.php">ascend-ppp-isdn-dos(7498)</ref>
    </refs>
    <vuln_soft>
      <prod name="multilink_ppp_for_isdn" vendor="ascend">
        <vers num="4.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1204" seq="1999-1204" published="1998-05-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default "ANY" address and result in access to more systems than intended by the administrator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925912&amp;w=2">19980511 Firewall-1 Reserved Keywords Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/config/keywords.html">http://www.checkpoint.com/techsupport/config/keywords.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7293">fw1-user-defined-keywords-access(7293)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1205" seq="1999-1205" published="1996-06-07" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167419195&amp;w=2">19960607 HP-UX B.10.01 vulnerability</ref>
      <ref source="HP" url="http://packetstormsecurity.org/advisories/ibm-ers/96-08" adv="1" patch="1">HPSBUX9607-035</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/414">hp-nettune(414)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1206" seq="1999-1206" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93336970231857&amp;w=2">19990729 New ActiveX security problems in Windows 98 PCs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/555">555</ref>
      <ref source="CONFIRM" url="http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm" adv="1" patch="1">http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="systemwizard" vendor="systemsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1207" seq="1999-1207" published="1998-02-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.efri.hr/~crv/security/bugs/NT/netxtray.html">http://www.efri.hr/~crv/security/bugs/NT/netxtray.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/907">netxray-bo(907)</ref>
    </refs>
    <vuln_soft>
      <prod name="netxray" vendor="network_general">
        <vers num="all_versions"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1208" seq="1999-1208" published="1997-07-21" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602661419330&amp;w=2">19970721 AIX ping (Exploit)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602661419337&amp;w=2">19970721 AIX ping, lchangelv, xlock fixes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/803">ping-bo(803)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1209" seq="1999-1209" published="1997-11-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88131151000069&amp;w=2">19971204 scoterm exploit</ref>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.14.scoterm" adv="1" patch="1">VB-97.14</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/690">sco-scoterm(690)</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="3.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1210" seq="1999-1210" published="1997-11-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87936891504885&amp;w=2">19971112 Digital Unix Security Problem</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/613">dec-xterm(613)</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="4.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1211" seq="1999-1211" published="1991-03-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-02.html" adv="1" patch="1">CA-1991-02</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/574">sun-intelnetd(574)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1212" seq="1999-1212" published="1991-03-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-02.html" adv="1" patch="1">CA-1991-02</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/574">sun-intelnetd(574)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.0.3"/>
        <vers num="4.0.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1213" seq="1999-1213" published="1997-10-01" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www2.dataguard.no/bugtraq/1997_4/0001.html" adv="1" patch="1">HPSBUX9710-070</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/571">hp-telnetdos(571)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1214" seq="1999-1214" published="1997-09-15" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.openbsd.com/advisories/signals.txt">http://www.openbsd.com/advisories/signals.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/556">openbsd-iosig(556)</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd" vendor="bsd">
        <vers num="4.4"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1215" seq="1999-1215" published="1993-09-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml">D-21</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-12.html" adv="1" patch="1">CA-1993-12</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/545">novell-login(545)</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="4.0"/>
        <vers num="4.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1216" seq="1999-1216" published="1993-04-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-15.shtml" adv="1" patch="1">D-15</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-07.html" adv="1" patch="1">CA-1993-07</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/541">cisco-sourceroute(541)</ref>
    </refs>
    <vuln_soft>
      <prod name="router" vendor="cisco">
        <vers num="8.2"/>
        <vers num="8.3"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
        <vers num="9.17" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1217" seq="1999-1217" published="1997-07-25" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=87602726319426&amp;w=2">19970723 NT security - why bother?</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=87602726319435&amp;w=2">19970725 Re: NT security - why bother?</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/526">nt-path(526)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1218" seq="1999-1218" published="1993-02-18" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-04.html" adv="1" patch="1">CA-1993-04</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/522">amiga-finger(522)</ref>
    </refs>
    <vuln_soft>
      <prod name="amiga_unix" vendor="commodore">
        <vers num="2.1p2a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1219" seq="1999-1219" published="1994-08-11" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-33.shtml" adv="1" patch="1">E-33</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1994-13.html" adv="1" patch="1">CA-1994-13</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/468" adv="1" patch="1">468</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/511">sgi-prn-mgr(511)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1220" seq="1999-1220" published="1997-08-24" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7527" adv="1">19970824 Vulnerability in Majordomo</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/502">majordomo-advertise(502)</ref>
    </refs>
    <vuln_soft>
      <prod name="majordomo" vendor="great_circle_associates">
        <vers num="1.94.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1221" seq="1999-1221" published="1996-11-17" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420141&amp;w=2">19961117 Digital Unix v3.x (v4.x?) security vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/399">dgux-chpwd(399)</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1222" seq="1999-1222" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q188/5/71.ASP" adv="1" patch="1">Q188571</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3893">dns-netbtsys-dos(3893)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":terminal_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1223" seq="1999-1223" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q187/5/03.asp" adv="1" patch="1">Q187503</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3892">url-asp-av(3892)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1224" seq="1999-1224" published="1997-10-08" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87635124302928&amp;w=2">19971008 L0pht Advisory: IMAP4rev1 imapd server</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/349">imapd-core(349)</ref>
    </refs>
    <vuln_soft>
      <prod name="imapd" vendor="university_of_washington">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1225" seq="1999-1225" published="1997-08-24" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7526">19970824 Serious security flaw in rpc.mountd on several operating systems.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/347">mountd-file-exists(347)</ref>
    </refs>
    <vuln_soft>
      <prod name="ultrix" vendor="digital">
        <vers num=""/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="2.0.4"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num=""/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1226" seq="1999-1226" published="1999-10-28" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3436">netscape-huge-key-dos(3436)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1227" seq="1999-1227" published="1999-07-30" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html" adv="1">http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html</ref>
      <ref source="MISC" url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html" adv="1">http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3334">ethereal-dev-capturec-root(3334)</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1228" seq="1999-1228" published="1998-09-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a "+++" sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90695973308453&amp;w=2">19980927 1+2=3, +++ATH0=Old school DoS</ref>
      <ref source="MISC" url="http://www.macintouch.com/modemsecurity.html" adv="1">http://www.macintouch.com/modemsecurity.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3320">global-village-modem-dos(3320)</ref>
    </refs>
    <vuln_soft>
      <prod name="quicktel" vendor="logicode">
        <vers num="28.8"/>
      </prod>
      <prod name="supra" vendor="diamond">
        <vers num="33.6"/>
        <vers num="v.90"/>
      </prod>
      <prod name="us_robotics" vendor="us_robotics">
        <vers num="33.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1229" seq="1999-1229" published="1998-02-25" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8590" adv="1">19980225 Quake 2 Linux 3.13 (and lower) allow users to read arbitrary files</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/733">linux-quake2(733)</ref>
    </refs>
    <vuln_soft>
      <prod name="quake_2_server" vendor="id_software">
        <vers num="3.13" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1230" seq="1999-1230" published="1997-12-24" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8282" adv="1" patch="1">19971224 Quake II Remote Denial of Service</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/698">quake2-dos(698)</ref>
    </refs>
    <vuln_soft>
      <prod name="quake_2" vendor="id_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1231" seq="1999-1231" published="1999-06-09" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14758" adv="1" patch="1">19990609 ssh advirsory</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2276">ssh-leak(2276)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh2" vendor="ssh">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1232" seq="1999-1232" published="1997-05-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420994&amp;w=2">19970516 Irix and WWW</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3316">sgi-day5datacopier(3316)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1233" seq="1999-1233" published="1999-12-31" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q241/5/62.asp" adv="1" patch="1">241562</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/657" adv="1" patch="1">657</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-039">MS99-039</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3306">iis-unresolved-domain-access(3306)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1234" seq="1999-1234" published="1999-10-26" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94096671308565&amp;w=2">19991026 Re: LSA vulnerability on NT40 SP5</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3293">msrpc-samr-open-dos(3293)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1235" seq="1999-1235" published="1999-08-25" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3289">nt-ie5-user-ftp-password(3289)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1236" seq="1999-1236" published="1999-10-01" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9910&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=662" adv="1">19991001 Vulnerabilities in the Internet Anywhere Mail Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/731" adv="1">731</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3285">iams-passwords-plaintext(3285)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_anywhere_mail_server" vendor="true_north">
        <vers num="2.3.1"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1237" seq="1999-1237" published="1999-06-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14384" adv="1">19990606 Buffer overflows in smbval library</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2272">smbvalid-bo(2272)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1238" seq="1999-1238" published="1994-09-21" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/advisories/1531" adv="1" patch="1">HPSBUX9409-017</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2262">hp-core-diag-fileset(2262)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="8"/>
        <vers num="9"/>
        <vers num="9.05" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1239" seq="1999-1239" published="1994-07-13" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/advisories/1559" adv="1" patch="1">HPSBUX9407-015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2261">hp-xauthority(2261)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1240" seq="1999-1240" published="1996-11-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2203">cddbd-bo(2203)</ref>
    </refs>
    <vuln_soft>
      <prod name="cddbd" vendor="gracenote">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1241" seq="1999-1241" published="1999-05-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html">http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2173">ie-filesystemobject(2173)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6.0.2900"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1242" seq="1999-1242" published="1994-02-07" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/003" adv="1" patch="1">HPSBUX9402-003</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2162">hp-subnet-config(2162)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="9.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1243" seq="1999-1243" published="1995-03-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373" adv="1" patch="1">19950301-01-P373</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml" adv="1" patch="1">F-16</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2113">sgi-permissions(2113)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1244" seq="1999-1244" published="1999-04-15" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary files via a symlink attack on the saved output file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13303" adv="1">19990415 FSA-99.04-IPFILTER-v3.2.10</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2087">ipfilter-temp-file(2087)</ref>
    </refs>
    <vuln_soft>
      <prod name="ipfilter" vendor="darren_reed">
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers num="3.2.9"/>
        <vers num="3.2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1245" seq="1999-1245" published="1999-04-06" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability was fixed in version 3.6 of ucd-snmpd.</sol>
    </sols>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2086">ucd-snmpd-community(2086)</ref>
    </refs>
    <vuln_soft>
      <prod name="ucd-snmp" vendor="ucd-snmp">
        <vers num="3.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1246" seq="1999-1246" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q229/9/72.asp" adv="1" patch="1">Q229972</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2068">siteserver-directmail-passwords(2068)</ref>
    </refs>
    <vuln_soft>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1247" seq="1999-1247" published="1999-02-24" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/006" patch="1">HPSBUX9402-006</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2061">hp-dce9000(2061)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1248" seq="1999-1248" published="1994-11-30" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/019" adv="1" patch="1">HPSBUX9411-019</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2058">hp-supportwatch(2058)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="8.00"/>
        <vers num="8.02"/>
        <vers num="8.06"/>
        <vers num="9.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1249" seq="1999-1249" published="1997-01-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html" adv="1" patch="1">HPSBUX9701-047</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2057">hp-movemail(2057)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1250" seq="1999-1250" published="1997-08-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7506" adv="1" patch="1">19970819 Lasso CGI security hole (fwd)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2044">http-cgi-lasso(2044)</ref>
    </refs>
    <vuln_soft>
      <prod name="lasso_cgi" vendor="blue_world_communications">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1251" seq="1999-1251" published="1996-12-24" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/043" adv="1" patch="1">HPSBUX9612-043</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2010">hp-audio-panic(2010)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1252" seq="1999-1252" published="1996-09-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.COM/SSE/security_bulletins/SB.96:02a">96:002</ref>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.15.sco" adv="1" patch="1">VB-96.15</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1966">sco-system-call(1966)</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="2.0.x"/>
        <vers num="2.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1253" seq="1999-1253" published="1996-06-07" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB.96:01a">96:001</ref>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.10.sco" adv="1" patch="1">VB-96.10</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1965">sco-kernel(1965)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_faststart" vendor="sco">
        <vers num="1.0"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1254" seq="1999-1254" published="1999-03-08" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92099515709467&amp;w=2">19990308 Winfreeze EXPLOIT  Win9x/NT</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1947">win-redirects-freeze(1947)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1255" seq="1999-1255" published="1999-02-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1914">hyperseek-modify(1914)</ref>
    </refs>
    <vuln_soft>
      <prod name="hyperseek_search_engine" vendor="ccs_network">
        <vers num="2000" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1256" seq="1999-1256" published="1999-03-04" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92056752115116&amp;w=2">19990304 Oracle Plaintext Password</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12744">19990304 Oracle Plaintext Password</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1902">oracle-passwords(1902)</ref>
    </refs>
    <vuln_soft>
      <prod name="database_assistant" vendor="oracle">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1257" seq="1999-1257" published="1997-11-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8134" adv="1">19971126 Xyplex terminal server bug</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1825">xyplex-controlz-login(1825)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1826">xyplex-question-login(1826)</ref>
    </refs>
    <vuln_soft>
      <prod name="maxserver_xyplex_terminal_server" vendor="xyplex">
        <vers num="6.0.1_s1"/>
        <vers num="6.0.2_s4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1258" seq="1999-1258" published="1991-01-15" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102" adv="1" patch="1">00102</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1782">sun-pwdauthd(1782)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
        <vers num="4.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1259" seq="1999-1259" published="1999-12-31" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q189/5/29.asp" adv="1" patch="1">Q189529</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1780">office-extraneous-data(1780)</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="98" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1260" seq="1999-1260" published="1999-02-15" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91910115718150&amp;w=2">19990215 KSR[T] Advisory #10: mSQL ServerStats</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1777">msql-serverstats(1777)</ref>
    </refs>
    <vuln_soft>
      <prod name="msql" vendor="hughes">
        <vers num="2.0.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1261" seq="1999-1261" published="1997-10-24" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12433">19990211 Rainbow Six Buffer Overflow.....</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1772">rainbowsix-nick-bo(1772)</ref>
    </refs>
    <vuln_soft>
      <prod name="metamail" vendor="metamail_corporation">
        <vers num="7.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1262" seq="1999-1262" published="1997-08-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12231">19990202 Unsecured server in applets under Netscape</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1727">java-socket-open(1727)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.01"/>
        <vers num="4.5"/>
        <vers num="4.06"/>
        <vers num="4.07"/>
        <vers num="4.08"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1263" seq="1999-1263" published="2003-08-15" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87773365324657&amp;w=2">19971024 Vulnerability in metamail</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1677">metamail-file-creation(1677)</ref>
    </refs>
    <vuln_soft>
      <prod name="metamail" vendor="metamail_corporation">
        <vers num="2.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1264" seq="1999-1264" published="1999-01-21" modified="2017-12-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91815321510224&amp;w=2">19990203 WebRamp M3 Perceived Bug</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12048">19990121 WebRamp M3 remote network access bug</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1670">webramp-remote-access(1670)</ref>
    </refs>
    <vuln_soft>
      <prod name="webramp" vendor="ramp_networks">
        <vers num="300"/>
        <vers num="m3"/>
        <vers num="m3i"/>
        <vers num="m3t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1265" seq="1999-1265" published="1998-09-22" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90649892424117&amp;w=2">19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=90650438826447&amp;w=2">19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1664">slmail-parens-overload(1664)</ref>
    </refs>
    <vuln_soft>
      <prod name="slmail" vendor="seatle_lab_software">
        <vers num="3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1266" seq="1999-1266" published="1997-06-13" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/6978" adv="1">19970613 rshd gives away usernames</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1660">rsh-username-leaks(1660)</ref>
    </refs>
    <vuln_soft>
      <prod name="metamail" vendor="metamail_corporation">
        <vers num="7.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1267" seq="1999-1267" published="1997-05-05" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420906&amp;w=2">19970505 Hole in the KDE desktop</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1646">kde-flawed-ipc(1646)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1268" seq="1999-1268" published="1999-01-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2" patch="1">http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1645">kde-konsole-hijack(1645)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1269" seq="1999-1269" published="1998-02-06" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8506" adv="1" patch="1">19980206 serious security hole in KDE Beta 3</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1641">kde-kss-file-clobber(1641)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde_beta_3" vendor="kde">
        <vers num="initial"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1270" seq="1999-1270" published="1998-07-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://lists.kde.org/?l=kde-devel&amp;m=90221974029738&amp;w=2" adv="1">http://lists.kde.org/?l=kde-devel&amp;m=90221974029738&amp;w=2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1639">kde-kmail-passphrase-leak(1639)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1271" seq="1999-1271" published="1998-06-11" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9511" adv="1">19980611 Unsecure passwords in Macromedia Dreamweaver</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1636">dreamweaver-weak-passwords(1636)</ref>
    </refs>
    <vuln_soft>
      <prod name="dreamweaver" vendor="macromedia">
        <vers num="initial"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1272" seq="1999-1272" published="1998-03-01" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX" adv="1" patch="1">19980301-01-PX</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1635">irix-cdrom-confidence(1635)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1273" seq="1999-1273" published="1998-02-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8551" adv="1" patch="1">19980220 Simple way to bypass squid ACLs</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1627">squid-regexp-acl(1627)</ref>
    </refs>
    <vuln_soft>
      <prod name="squid_web_proxy" vendor="national_science_foundation">
        <vers num="1.1.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1274" seq="1999-1274" published="1997-12-29" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">iPass RoamServer 3.1 creates temporary files with world-writable permissions.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8307" adv="1">19971229 iPass RoamServer 3.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1625">ipass-temporary-files(1625)</ref>
    </refs>
    <vuln_soft>
      <prod name="roamserver" vendor="ipass">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1275" seq="1999-1275" published="1997-09-08" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9478" adv="1">19970908 Password unsecurity in cc:Mail release 8</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1619">lotus-ccmail-passwords(1619)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_cc_mail" vendor="ibm">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1276" seq="1999-1276" published="1998-12-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/1998/19981207" adv="1" patch="1">19981207 fte-console: does not drop its root priviliges</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1609">fte-console-privileges(1609)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.6.20.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1277" seq="1999-1277" published="1998-12-24" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91487886514546&amp;w=2">19981224 BackWeb - Password issue (used by NAI for Corporate customer notification).</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1565">backweb-cleartext-passwords(1565)</ref>
    </refs>
    <vuln_soft>
      <prod name="backweb_client" vendor="backweb_technologies">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1278" seq="1999-1278" published="1998-12-25" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91470326629357&amp;w=2">19981225 Re: Nlog v1.0 Released - Nmap 2.x log management / analyzing tool</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91471400632145&amp;w=2">19981226 Nlog 1.1b released - security holes fixed</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1549">http-cgi-nlog-metachars(1549)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1550">http-cgi-nlog-netbios(1550)</ref>
    </refs>
    <vuln_soft>
      <prod name="nlog" vendor="nlog">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1279" seq="1999-1279" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q138/0/01.asp" adv="1" patch="1">Q138001</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1548">snaserver-shared-folders(1548)</ref>
    </refs>
    <vuln_soft>
      <prod name="sna_server" vendor="microsoft">
        <vers num="2.11"/>
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1280" seq="1999-1280" published="1998-12-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11512" adv="1" patch="1">19981203 Remote Tools w/Exceed v.6.0.1.0 fer 95</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1547">exceed-cleartext-passwords(1547)</ref>
    </refs>
    <vuln_soft>
      <prod name="exceed" vendor="hummingbird">
        <vers num="6.0.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1281" seq="1999-1281" published="1998-12-26" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11720" adv="1">19981226 Breeze Network Server remote reboot and other bogosity.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1544">breeze-remote-reboot(1544)</ref>
    </refs>
    <vuln_soft>
      <prod name="breeze_network_server" vendor="winddance_networks_corporation">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1282" seq="1999-1282" published="1998-12-10" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11543" adv="1" patch="1">19981210 RealSystem passwords</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1542">realsystem-readable-conf-file(1542)</ref>
    </refs>
    <vuln_soft>
      <prod name="realsystem_g2_server" vendor="realnetworks">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1283" seq="1999-1283" published="1998-08-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10320" adv="1">19980814 URL exploit to crash Opera Browser</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1541">opera-slash-crash(1541)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1284" seq="1999-1284" published="1998-11-05" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91063407332594&amp;w=2">19981107 Re: various *lame* DoS attacks</ref>
      <ref source="MISC" url="http://www.dynamsol.com/puppet/text/new.txt">http://www.dynamsol.com/puppet/text/new.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11131" adv="1">19981105 various *lame* DoS attacks</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1540">nukenabber-timeout-dos(1540)</ref>
    </refs>
    <vuln_soft>
      <prod name="nukenabber" vendor="puppets_place">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1285" seq="1999-1285" published="1998-12-27" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91495921611500&amp;w=2">19981227 [patch] fix for urandom read(2) not interruptible</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1472">linux-random-read-dos(1472)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.1.132" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1286" seq="1999-1286" published="1997-05-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420927&amp;w=2">19970509 Re: Irix: misc</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/330">330</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1433">irix-addnetpr(1433)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1287" seq="1999-1287" published="1999-12-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.statslab.cam.ac.uk/~sret1/analog/security.html" adv="1">http://www.statslab.cam.ac.uk/~sret1/analog/security.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1410">analog-remote-file(1410)</ref>
    </refs>
    <vuln_soft>
      <prod name="analog" vendor="stephen_turner">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1288" seq="1999-1288" published="1998-11-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/SA-1998.35.txt" adv="1" patch="1">SA-1998.35</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11397">19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1406">samba-wsmbconf(1406)</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="1.9.18"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1289" seq="1999-1289" published="1998-11-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11233" adv="1">19981111 WARNING: Another ICQ IP address vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1398">icq-ip-info(1398)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="98_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1290" seq="1999-1290" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91127951426494&amp;w=2">19981117 nftp vulnerability (fwd)</ref>
      <ref source="CONFIRM" url="http://www.ayukov.com/nftp/history.html" adv="1" patch="1">http://www.ayukov.com/nftp/history.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1397">nftp-bo(1397)</ref>
    </refs>
    <vuln_soft>
      <prod name="nftp" vendor="chris_matthee">
        <vers num="1.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1291" seq="1999-1291" published="1998-10-05" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10789" adv="1">19981005 New Windows Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1383">nt-brkill(1383)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1292" seq="1999-1292" published="1998-09-01" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise7.php" adv="1">19980901 Remote Buffer Overflow in the Kolban Webcam32 Program</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1366">webcam32-buffer-overflow(1366)</ref>
    </refs>
    <vuln_soft>
      <prod name="webcam32" vendor="kolban">
        <vers num="4.8.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1293" seq="1999-1293" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88413292830649&amp;w=2">19980106 Apache security advisory</ref>
      <ref source="CONFIRM" url="http://www.apache.org/info/security_bulletin_1.2.5.html" adv="1" patch="1">http://www.apache.org/info/security_bulletin_1.2.5.html</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.2.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1294" seq="1999-1294" published="1999-12-31" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q146/6/04.asp" adv="1" patch="1">Q146604</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/562">nt-filemgr(562)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1295" seq="1999-1295" published="1996-09-17" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.16.transarc" adv="1" patch="1">VB-96.16</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7154">dfs-login-groups(7154)</ref>
    </refs>
    <vuln_soft>
      <prod name="dce_distributed_file_system" vendor="transarc">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1296" seq="1999-1296" published="1997-04-29" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420878&amp;w=2">19970429 vulnerabilities in kerberos</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1297" seq="1999-1297" published="1998-07-15" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100452&amp;zone_32=10045%2A%20" patch="1">1077164</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7482">sun-cmdtool-echo(7482)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1298" seq="1999-1298" published="1997-04-07" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc" adv="1" patch="1">FreeBSD-SA-97:03</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7537.php">freebsd-sysinstall-ftp-password(7537)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.2"/>
        <vers num="2.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1299" seq="1999-1299" published="1997-02-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420509&amp;w=2">19970203 Linux rcp bug</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1300" seq="1999-1300" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-31.shtml" adv="1" patch="1">B-31</ref>
    </refs>
    <vuln_soft>
      <prod name="unicos" vendor="cray">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1301" seq="1999-1301" published="1996-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc" adv="1" patch="1">FreeBSD-SA-96:17</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml" adv="1" patch="1">G-31</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7540.php">rzsz-command-execution(7540)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1302" seq="1999-1302" published="1994-11-30" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
      <ref source="CERT" url="http://ftp.cerias.purdue.edu/pub/advisories/cert/cert_bulletins/VB-94:01.sco">VB-94:01</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7586">sco-pt_chmod(7586)</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
      <prod name="open_desktop_lite" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_enterprise_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_network_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1303" seq="1999-1303" published="1994-11-30" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
      <prod name="open_desktop_lite" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_enterprise_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_network_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1304" seq="1999-1304" published="1994-11-30" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
      <prod name="open_desktop_lite" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_enterprise_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_network_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1305" seq="1999-1305" published="1994-11-30" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
      <prod name="open_desktop_lite" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_enterprise_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="openserver_network_system" vendor="sco">
        <vers num="3.0"/>
      </prod>
      <prod name="unix" vendor="sco">
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1306" seq="1999-1306" published="1992-12-10" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-20.html" adv="1" patch="1">CA-1992-20</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1307" seq="1999-1307" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-06.shtml" adv="1" patch="1">F-06</ref>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_4/0676.html" adv="1">19941209 Novell security advisory on sadc, urestore and the suid_exec feature</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="novell">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1308" seq="1999-1308" published="1997-07-31" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-09.shtml">H-09</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-91.shtml">H-91</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7594.php">hp-large-uid-gid(7594)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1309" seq="1999-1309" published="1996-08-30" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities" adv="1" patch="1">CA-1994-12</ref>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0040.html" adv="1">19940314 sendmail -d problem (OLD yet still here)</ref>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0042.html" adv="1">19940315 anyone know details?</ref>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0043.html">19940315 so...</ref>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0048.html" adv="1">19940315 Security problem in sendmail versions 8.x.x</ref>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0078.html">19940327 sendmail exploit script - resend</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7155">sendmail-debug-gain-root(7155)</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.6.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1310" seq="1999-1310" published="1994-11-04" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1022.  Reason: This candidate is a duplicate of CVE-1999-1022.  Notes: All CVE users should reference CVE-1999-1022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-1999-1311" seq="1999-1311" published="1997-01-07" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1312" seq="1999-1312" published="1993-02-24" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-05.html" adv="1" patch="1">CA-1993-05</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7142">openvms-local-privilege-elevation(7142)</ref>
    </refs>
    <vuln_soft>
      <prod name="dec_openvms_axp" vendor="dec">
        <vers num="1.0"/>
      </prod>
      <prod name="dec_openvms_vax" vendor="dec">
        <vers num="5.5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1313" seq="1999-1313" published="1996-05-23" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:11.man.asc" adv="1" patch="1">FreeBSD-SA-96:11</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml" adv="1" patch="1">G-24</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7348">bsd-man-command-sequence(7348)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1314" seq="1999-1314" published="1996-05-17" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:10.mount_union.asc" adv="1" patch="1">FreeBSD-SA-96:10</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7429.php">unionfs-mount-ordering(7429)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1" edition="stable"/>
        <vers num="2.1.0"/>
        <vers num="2.2" prev="1" edition="current"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1315" seq="1999-1315" published="1999-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-04.shtml" adv="1" patch="1">F-04</ref>
    </refs>
    <vuln_soft>
      <prod name="dec_openvms" vendor="dec">
        <vers num="5.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1316" seq="1999-1316" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q247/9/75.asp" adv="1" patch="1">Q247975</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7391">passfilt-fullname(7391)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp2:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1317" seq="1999-1317" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92127046701349&amp;w=2">19990312 [ ALERT ] Case Sensitivity and Symbolic Links</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92162979530341&amp;w=2">19990314 AW: [ ALERT ] Case Sensitivity and Symbolic Links</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q222/1/59.asp" adv="1" patch="1">Q222159</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7398">nt-symlink-case(7398)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1318" seq="1999-1318" published="1993-09-17" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20" adv="1" patch="1">1121935</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7480.php">sun-su-path(7480)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1319" seq="1999-1319" published="1996-01-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19960101-01-PX" adv="1" patch="1">19960101-01-PX</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7430.php">irix-object-server(7430)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1320" seq="1999-1320" published="1999-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-01.shtml" adv="1" patch="1">D-01</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7213.php">netware-packet-spoofing-privileges(7213)</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1321" seq="1999-1321" published="1998-11-05" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://lists.netspace.org/cgi-bin/wa?A2=ind9811A&amp;L=bugtraq&amp;P=R4814">19981105 security patch for ssh-1.2.26 kerberos code</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="v"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1322" seq="1999-1322" published="1998-11-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91096758513985&amp;w=2">19981112 exchverify.log</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91133714919229&amp;w=2">19981117 Re: exchverify.log - update #1</ref>
    </refs>
    <vuln_soft>
      <prod name="arcserve_backup" vendor="ca">
        <vers num=""/>
      </prod>
      <prod name="inoculan" vendor="ca">
        <vers num=""/>
      </prod>
      <prod name="exchange_server" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1323" seq="1999-1323" published="1999-04-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92370067416739&amp;w=2">19990409 NAV for MS Exchange &amp; Internet Email Gateways</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="1.0.1.7" prev="1" edition=":internet_email_gateways"/>
        <vers num="1.5" prev="1" edition=":exchange"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1324" seq="1999-1324" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-06.shtml" adv="1" patch="1">D-06</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7225">openvms-sysgen-enabled(7225)</ref>
    </refs>
    <vuln_soft>
      <prod name="dec_openvms_vax" vendor="dec">
        <vers num="5.3"/>
        <vers num="5.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1325" seq="1999-1325" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/c-19.shtml" adv="1">C-19</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7261">vaxvms-sas-gain-privileges(7261)</ref>
    </refs>
    <vuln_soft>
      <prod name="sas_system" vendor="vax_vms">
        <vers num="5.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1326" seq="1999-1326" published="1997-07-04" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420401&amp;w=2">19970104 serious security bug in wu-ftpd v2.4</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420408&amp;w=2">19970105 BoS:  serious security bug in wu-ftpd v2.4 -- PATCH</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7169">wuftpd-abor-gain-privileges(7169)</ref>
    </refs>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1327" seq="1999-1327" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125826&amp;w=2">19980601 Re: SECURITY: Red Hat Linux 5.1 linuxconf bug (fwd)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7239.php">linuxconf-lang-bo(7239)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1328" seq="1999-1328" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90383955231511&amp;w=2">19980823 Security concerns in linuxconf shipped w/RedHat 5.1</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7232.php">linuxconf-symlink-gain-privileges(7232)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1329" seq="1999-1329" published="1999-12-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7250.php">sysvinit-root-bo(7250)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit">http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1330" seq="1999-1330" published="1999-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html">http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602661419259&amp;w=2">19970709 [linux-security] so-called snprintf() in db-1.85.4 (fwd)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7244.php">linux-libdb-snprintf-bo(7244)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#db">http://www.redhat.com/support/errata/rh42-errata-general.html#db</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1331" seq="1999-1331" published="1999-12-31" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7245.php">netcfg-ethernet-dos(7245)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg">http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1332" seq="1999-1332" published="1999-12-31" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88603844115233&amp;w=2">19980128 GZEXE - the big problem</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-308">DSA-308</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7241.php">gzip-gzexe-tmp-symlink(7241)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#gzip">http://www.redhat.com/support/errata/rh50-errata-general.html#gzip</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7845">7845</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1333" seq="1999-1333" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89042322924057&amp;w=2">19980319 ncftp 2.4.2 MkDirs bug</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7240.php">ncftp-autodownload-command-execution(7240)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp">http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1334" seq="1999-1334" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88609666024181&amp;w=2">19980129 KSR[T] Advisory #7: filter</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#elm">http://www.redhat.com/support/errata/rh50-errata-general.html#elm</ref>
    </refs>
    <vuln_soft>
      <prod name="elm" vendor="elm_development_group">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1335" seq="1999-1335" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp">http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7251">cmusnmp-read-write(7251)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1336" seq="1999-1336" published="1999-08-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93458364903256&amp;w=2">19990812 3com hiperarch flaw [hiperbomb.c]</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93492615408725&amp;w=2">19990816 Re: 3com hiperarch flaw [hiperbomb.c]</ref>
    </refs>
    <vuln_soft>
      <prod name="hiperarc" vendor="3com">
        <vers num="4.2.29" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1337" seq="1999-1337" published="1999-08-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93370073207984&amp;w=2">19990801 midnight commander vulnerability(?) (fwd)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/9873.php">midnight-commander-data-disclosure(9873)</ref>
    </refs>
    <vuln_soft>
      <prod name="midnight_commander" vendor="midnight_commander">
        <vers num="4.5.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1338" seq="1999-1338" published="1999-07-21" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93259112204664&amp;w=2">19990721 Delegate creates directories writable for anyone</ref>
    </refs>
    <vuln_soft>
      <prod name="delegate" vendor="delegate">
        <vers num="5.9.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1339" seq="1999-1339" published="1999-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93277426802802&amp;w=2">19990722 Linux +ipchains+ ping -R</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93277766505061&amp;w=2">19990722 Re: ping -R causes kernel panic on a forwarding machine ( 2.2.5 a nd 2 .2.10)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7257.php">ipchains-ping-route-dos(7257)</ref>
      <ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz">http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.2"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1340" seq="1999-1340" published="1999-11-04" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94173799532589&amp;w=2">19991104 hylafax-4.0.2 local exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/765" adv="1">765</ref>
    </refs>
    <vuln_soft>
      <prod name="hylafax" vendor="hylafax">
        <vers num="4.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1341" seq="1999-1341" published="1999-10-22" modified="2018-09-11" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94061108411308&amp;w=2" adv="1">19991022 Local user can send forged packets</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7858" adv="1">linux-tiocsetd-forge-packets(7858)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.13"/>
        <vers num="2.3.14"/>
        <vers num="2.3.15"/>
        <vers num="2.3.16"/>
        <vers num="2.3.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1342" seq="1999-1342" published="1999-10-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94042342010662&amp;w=2">19991017 ICQ ActiveList Server Exploit...</ref>
    </refs>
    <vuln_soft>
      <prod name="activelist_server" vendor="icq">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1343" seq="1999-1343" published="1999-10-13" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93986405412867&amp;w=2">19991013 Xerox DocuColor 4 LP D.O.S</ref>
    </refs>
    <vuln_soft>
      <prod name="docucolor_4lp" vendor="xerox">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1344" seq="1999-1344" published="1999-10-05" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Auto_FTP.pl script in Auto_FTP 0.2 stores usernames and passwords in plaintext in the auto_ftp.conf configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93923873006014&amp;w=2">19991005 Auto_FTP v0.02 Advisory</ref>
    </refs>
    <vuln_soft>
      <prod name="auto_ftp" vendor="auto_ftp">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1345" seq="1999-1345" published="1999-10-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93923873006014&amp;w=2">19991005 Auto_FTP v0.02 Advisory</ref>
    </refs>
    <vuln_soft>
      <prod name="auto_ftp" vendor="auto_ftp">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1346" seq="1999-1346" published="1999-10-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93942774609925&amp;w=2">19991007 Problems with redhat 6 Xsession and pam.d/rlogin.</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1347" seq="1999-1347" published="1999-10-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93942774609925&amp;w=2">19991007 Problems with redhat 6 Xsession and pam.d/rlogin.</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1348" seq="1999-1348" published="1999-06-30" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93220073515880&amp;w=2">19990630 linuxconf doesn't seem to deal correctly with /etc/pam.d/reboot</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1349" seq="1999-1349" published="1999-10-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93923679004325&amp;w=2">19991006 Omni-NFS/X Enterprise  (nfsd.exe) DOS</ref>
    </refs>
    <vuln_soft>
      <prod name="omni-nfs_x_enterprise" vendor="xlink_technology">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1350" seq="1999-1350" published="1999-09-29" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93871933521519&amp;w=2">19990929 Multiple Vendor ARCAD permission problems</ref>
    </refs>
    <vuln_soft>
      <prod name="arcad" vendor="arcad_systemhaus">
        <vers num="0.078_5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1351" seq="1999-1351" published="1999-09-24" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick &lt;soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93845560631314&amp;w=2">19990924 Kvirc bug</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7761.php">kvirc-dot-directory-traversal(7761)</ref>
    </refs>
    <vuln_soft>
      <prod name="irc_client" vendor="kvirc">
        <vers num="0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1352" seq="1999-1352" published="1999-09-28" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93855134409747&amp;w=2">19990928 Re: [Fwd: Truth about ssh 1.2.27 vulnerabiltiy]</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1353" seq="1999-1353" published="1999-09-07" modified="2017-04-28" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93698162708211&amp;w=2">19990907 MsgCore mailserver stores passwords in clear text</ref>
    </refs>
    <vuln_soft>
      <prod name="msgcore" vendor="nosque">
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1354" seq="1999-1354" published="1999-08-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93637687305327&amp;w=2">19990830 SoftArc's FirstClass E-mail Client</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93698283309513&amp;w=2">19990909 SoftArc's FirstClass E-mail Client</ref>
    </refs>
    <vuln_soft>
      <prod name="firstclass_internet_server" vendor="softarc">
        <vers num="5.506" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1355" seq="1999-1355" published="1999-12-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93542118727732&amp;w=2">19990817 Compaq PFCUser account</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93654336516711&amp;w=2">19990905 Case ID  SSRT0620  - PFCUser account communication</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93759822430801&amp;w=2">19990915 (I) UPDATE - PFCUser Account,</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94183795025294&amp;w=2">19991105 UPDATE: SSRT0620 Compaq Foundation Agents v4.40B  PFCUser issues</ref>
      <ref source="CONFIRM" url="http://www.compaq.com/products/servers/management/advisory.html" adv="1">http://www.compaq.com/products/servers/management/advisory.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3231">management-pfcuser(3231)</ref>
    </refs>
    <vuln_soft>
      <prod name="insight_management_agent" vendor="compaq">
        <vers num="4.20" prev="1"/>
      </prod>
      <prod name="management_agents_for_servers" vendor="compaq">
        <vers num="4.40" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1356" seq="1999-1356" published="1999-09-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93646669500991&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93637792706047&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93759822830815&amp;w=2">19990917 Re: Compaq CIM UG Overwrites Legal Notice</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7763.php">compaq-smartstart-legal-notice(7763)</ref>
    </refs>
    <vuln_soft>
      <prod name="smartstart" vendor="compaq">
        <vers num="4.50" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1357" seq="1999-1357" published="1999-10-05" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "&lt;" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93915331626185&amp;w=2">19991005 Time to update those CGIs again</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.04"/>
        <vers num="4.7" prev="1"/>
        <vers num="4.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1358" seq="1999-1358" published="1999-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q157/6/73.asp" adv="1" patch="1">Q157673</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7400.php">nt-user-policy-update(7400)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1359" seq="1999-1359" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/75.asp" adv="1" patch="1">Q163875</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7401.php">nt-group-policy-longname(7401)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1360" seq="1999-1360" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/50.asp" adv="1" patch="1">Q160650</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7402.php">nt-kernel-handle-dos(7402)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1361" seq="1999-1361" published="1998-05-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925891&amp;w=2">19980509 coke.c</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1362" seq="1999-1362" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/01.asp" adv="1" patch="1">Q160601</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7403.php">nt-win32k-dos(7403)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1363" seq="1999-1363" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/1/43.asp" adv="1" patch="1">Q163143</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7405.php">nt-nonpagedpool-dos(7405)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="3.5.1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1364" seq="1999-1364" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q142/6/53.asp" adv="1" patch="1">Q142653</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7421.php">nt-threadcontext-dos(7421)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1365" seq="1999-1365" published="1999-06-28" modified="2017-10-25" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93069418400856&amp;w=2">19990628 NT runs Explorer.exe, Taskmgr.exe etc. from wrong location</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93127894731200&amp;w=2">19990630 Update: NT runs explorer.exe, etc...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/515">515</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2336">nt-login-default-folder(2336)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1366" seq="1999-1366" published="1999-05-15" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92714118829880&amp;w=2">19990515 Pegasus Mail weak encryption</ref>
    </refs>
    <vuln_soft>
      <prod name="pegasus_mail" vendor="david_harris">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1367" seq="1999-1367" published="1999-05-06" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.pcworld.com/news/article/0,aid,10842,00.asp" adv="1" patch="1">http://www.pcworld.com/news/article/0,aid,10842,00.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1368" seq="1999-1368" published="1999-05-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92652152723629&amp;w=2">19990512 InoculateIT 4.53 Real-Time Exchange Scanner Flawed</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=97439568517355&amp;w=2">20001116 InoculateIT AV Option for MS Exchange Server</ref>
    </refs>
    <vuln_soft>
      <prod name="inoculateit" vendor="ca">
        <vers num="4.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1369" seq="1999-1369" published="1999-04-14" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92411181619110&amp;w=2">19990414 Real Media Server stores passwords in plain text</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver" vendor="realnetworks">
        <vers num="6.0.3.353"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1370" seq="1999-1370" published="1999-03-23" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92220197414799&amp;w=2">19990323 MSIE 5 installer disables screen saver</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1371" seq="1999-1371" published="1999-03-08" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92100752221493&amp;w=2">19990308 Solaris "/usr/bin/write" bug</ref>
      <ref source="MISC" url="http://www.securiteam.com/exploits/5ZP0O1P35O.html">http://www.securiteam.com/exploits/5ZP0O1P35O.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7546">solaris-write-bo(7546)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1372" seq="1999-1372" published="1999-02-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91966339502073&amp;w=2">19990219 Plaintext Password in Tractive's Remote Manager Software</ref>
    </refs>
    <vuln_soft>
      <prod name="remote_management" vendor="triactive">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1373" seq="1999-1373" published="2005-01-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91651770130771&amp;w=2">19990105 Re: Network Scan Vulnerability [SUMMARY]</ref>
    </refs>
    <vuln_soft>
      <prod name="powerhub_software" vendor="fore">
        <vers num="5.0.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1374" seq="1999-1374" published="2005-05-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92523159819402&amp;w=2">19990427 Re: Shopping Carts exposing CC data</ref>
    </refs>
    <vuln_soft>
      <prod name="perlshop" vendor="arpanet">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1375" seq="1999-1375" published="1999-02-11" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91877455626320&amp;w=2">19990211 Using FSO in ASP to view just about anything</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/230" adv="1">230</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1376" seq="1999-1376" published="1999-01-14" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91638375309890&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91632724913080&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1377" seq="1999-1377" published="1999-09-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://pulhas.org/phrack/55/P55-07.html" adv="1">http://pulhas.org/phrack/55/P55-07.html</ref>
    </refs>
    <vuln_soft>
      <prod name="download.cgi" vendor="matt_wright">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1378" seq="1999-1378" published="1999-07-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93250710625956&amp;w=2">19990917 improper chroot in dbmlparser.exe</ref>
    </refs>
    <vuln_soft>
      <prod name="dbmlparser.exe" vendor="dbmlparser.exe">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1379" seq="1999-1379" published="1999-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos" adv="1" patch="1">AL-1999.004</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-063.shtml" adv="1" patch="1">J-063</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93348057829957&amp;w=2">19990730 Possible Denial Of Service using DNS</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93433758607623&amp;w=2">19990810 Possible Denial Of Service using DNS</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7238.php">dns-udp-query-dos(7238)</ref>
    </refs>
    <vuln_soft>
      <prod name="dnstools" vendor="dnstools_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1380" seq="1999-1380" published="1997-05-04" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://mlarchive.ima.com/win95/1997/May/0342.html" adv="1" patch="1">http://mlarchive.ima.com/win95/1997/May/0342.html</ref>
      <ref source="MISC" url="http://news.zdnet.co.uk/story/0,,s2065518,00.html" adv="1">http://news.zdnet.co.uk/story/0,,s2065518,00.html</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7188.php">nu-tuneocx-activex-control(7188)</ref>
      <ref source="MISC" url="http://www.net-security.sk/bugs/NT/nu20.html">http://www.net-security.sk/bugs/NT/nu20.html</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_utilities" vendor="symantec">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1381" seq="1999-1381" published="1998-10-08" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90786656409618&amp;w=2">19981008 buffer overflow in dbadmin</ref>
    </refs>
    <vuln_soft>
      <prod name="dbadmin" vendor="dbadmin">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1382" seq="1999-1382" published="1999-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88427711321769&amp;w=2">19980108 NetWare NFS</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90295697702474&amp;w=2">19980812 Re: Netware NFS (fwd)</ref>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551" adv="1" patch="1">http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7246.php">netware-nfs-file-ownership(7246)</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1383" seq="1999-1383" published="1996-09-13" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167419868&amp;w=2">19960913 tee see shell problems</ref>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1996_3/0503.html" adv="1" patch="1">19960919 Vulnerability in expansion of PS1 in bash &amp; tcsh</ref>
    </refs>
    <vuln_soft>
      <prod name="bash" vendor="gnu">
        <vers num="1.14.0"/>
        <vers num="1.14.1"/>
        <vers num="1.14.2"/>
        <vers num="1.14.3"/>
        <vers num="1.14.4"/>
        <vers num="1.14.5"/>
        <vers num="1.14.6" prev="1"/>
      </prod>
      <prod name="tcsh" vendor="tcsh">
        <vers num="6.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1384" seq="1999-1384" published="1996-10-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul" adv="1" patch="1">AA-96.08</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I" adv="1" patch="1">19961101-01-I</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420095&amp;w=2">19961030 (Another) vulnerability in new SGIs</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7456.php">irix-systour(7456)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/470" adv="1" patch="1">470</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1385" seq="1999-1385" published="1996-12-19" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc" adv="1" patch="1">FreeBSD-SA-96:20</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420332&amp;w=2">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7465.php">ppp-bo(7465)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="2.1.0" prev="1"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1386" seq="1999-1386" published="1999-12-31" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88932165406213&amp;w=2">19980308 another /tmp race: `perl -e' opens temp file not safely</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7243.php">perl-e-tmp-symlink(7243)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#perl">http://www.redhat.com/support/errata/rh50-errata-general.html#perl</ref>
    </refs>
    <vuln_soft>
      <prod name="perl" vendor="larry_wall">
        <vers num="5.4.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1387" seq="1999-1387" published="1997-04-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420731&amp;w=2">19970402 Fatal bug in NT 4.0 server</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420732&amp;w=2">19970403 Fatal bug in NT 4.0 server (more comments)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420741&amp;w=2">19970407 DUMP of NT system crash</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1388" seq="1999-1388" published="1994-05-13" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_4/0755.html" adv="1" patch="1">19941218 Sun Patch Id #102060-01</ref>
      <ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1994_2/0197.html" adv="1" patch="1">19940513 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994</ref>
      <ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1994_2/0207.html" patch="1">19940514 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1389" seq="1999-1389" published="1998-05-11" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925916&amp;w=2">19980511 3Com/USR Total Control Chassis dialup port access filters</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/99" adv="1">99</ref>
    </refs>
    <vuln_soft>
      <prod name="total_control_netserver_card" vendor="3com">
        <vers num="3.7.24" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1390" seq="1999-1390" published="1998-04-28" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://darwin.bio.uci.edu/~mcoogan/bugtraq/msg00890.html" adv="1" patch="1">19980428 [Debian 2.0] /usr/bin/suidexec gives root access</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/94">94</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1391" seq="1999-1391" published="1990-10-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" adv="1" patch="1">B-01</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html" adv="1" patch="1">CA-1990-06</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7143.php">nextstep-npd-root-access(7143)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/10">10</ref>
    </refs>
    <vuln_soft>
      <prod name="next" vendor="next">
        <vers num="1.0"/>
        <vers num="1.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1392" seq="1999-1392" published="1990-10-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml" adv="1" patch="1">B-01</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html" adv="1" patch="1">CA-1990-06</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7144.php">nextstep-restore09-root-access(7144)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/9" adv="1" patch="1">9</ref>
    </refs>
    <vuln_soft>
      <prod name="nex" vendor="next">
        <vers num="1.0a"/>
      </prod>
      <prod name="next" vendor="next">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1393" seq="1999-1393" published="1999-05-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html" adv="1">http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/532" adv="1">532</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num="8.5"/>
        <vers num="8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1394" seq="1999-1394" published="1999-07-02" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93094058620450&amp;w=2">19990702 BSD-fileflags</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/510">510</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd" vendor="bsd">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1395" seq="1999-1395" published="1992-11-17" modified="2009-10-31" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-18.html" adv="1" patch="1">CA-1992-18</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability" adv="1" patch="1">CA-92.16</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/51">51</ref>
    </refs>
    <vuln_soft>
      <prod name="dec_openvms" vendor="dec">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.2"/>
        <vers num="5.1b"/>
        <vers num="5.2"/>
        <vers num="5.2.1"/>
        <vers num="5.3"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="5.4"/>
        <vers num="5.4.1"/>
        <vers num="5.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1396" seq="1999-1396" published="1992-07-21" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html" adv="1" patch="1">CA-1992-15</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7150.php">sun-integer-multiplication-access(7150)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/49">49</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1397" seq="1999-1397" published="1999-03-23" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92242671024118&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92223293409756&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7559.php">iis-indexserver-reveal-path(7559)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/476">476</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1398" seq="1999-1398" published="1997-05-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420921&amp;w=2">19970507 Irix: misc</ref>
      <ref source="MISC" url="http://www.insecure.org/sploits/irix.xfsdump.html">http://www.insecure.org/sploits/irix.xfsdump.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/472" adv="1" patch="1">472</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1399" seq="1999-1399" published="1997-08-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602746719552&amp;w=2">19970820 SpaceWare 7.3 v1.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/471" adv="1" patch="1">471</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1400" seq="1999-1400" published="1999-06-03" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0007.html" adv="1">19990603 Huge Exploit in NT 4.0 SP5 Screensaver with Password Protection Enabled</ref>
      <ref source="NTBUGTRAQ" url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0009.html" adv="1">19990603 Re: Huge Exploit in NT 4.0 SP5 Screensaver with Password Protecti on Enabled.</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92851653600852&amp;w=2">19990604 Official response from The Economist re: 1999 Screen Saver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/466">466</ref>
    </refs>
    <vuln_soft>
      <prod name="the_economist_1999_screen_saver" vendor="the_economist">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1401" seq="1999-1401" published="1996-12-05" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961201-01-PX" adv="1" patch="1">19961201-01-PX</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7575.php">irix-searchbook-permissions(7575)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/463" adv="1" patch="1">463</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1402" seq="1999-1402" published="1997-05-17" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167418317&amp;w=2">19970517 UNIX domain socket (Solarisx86 2.5)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602248718482&amp;w=2">19971003 Solaris 2.6 and sockets</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7172.php">sun-domain-socket-permissions(7172)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/456" adv="1" patch="1">456</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1403" seq="1999-1403" published="1998-10-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10771" adv="1">19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/382">382</ref>
    </refs>
    <vuln_soft>
      <prod name="tivoli_opc_tracker_agent" vendor="ibm">
        <vers num="1.0x"/>
        <vers num="2.0x"/>
        <vers num="3.0x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1404" seq="1999-1404" published="1998-10-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10771" adv="1">19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/382">382</ref>
    </refs>
    <vuln_soft>
      <prod name="tivoli_opc_tracker_agent" vendor="ibm">
        <vers num="1.0x"/>
        <vers num="2.0x"/>
        <vers num="3.0x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1405" seq="1999-1405" published="1999-02-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in AIX 4.3 and 4.3.2
AIX 4.3.x APAR: IX88263
AIX 4.2.x APAR: IX88261</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91936783009385&amp;w=2">19990217 snap utility for AIX.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91954824614013&amp;w=2">19990220 Re: snap utility for AIX.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/375">375</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1406" seq="1999-1406" published="1998-07-29" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526185&amp;w=2">19980729 Crash a redhat 5.1 linux box</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526192&amp;w=2">19980730 FD's 0..2 and suid/sgid procs (Was: Crash a redhat 5.1 linux box)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/372">372</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1407" seq="1999-1407" published="1998-03-09" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88950856416985&amp;w=2">19980309 *sigh* another RH5 /tmp problem</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7294.php">initscripts-ifdhcpdone-dhcplog-symlink(7294)</ref>
      <ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts">http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/368">368</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1408" seq="1999-1408" published="1997-03-05" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420641&amp;w=2">19970305 Bug in connect() for aix 4.1.4 ?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/352" adv="1" patch="1">352</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.05"/>
        <vers num="10.01"/>
        <vers num="10.20"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1409" seq="1999-1409" published="1998-07-03" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc">NetBSD-SA1998-004</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90233906612929&amp;w=2">19980805 irix-6.2 "at -f" vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7577.php">at-f-read-files(7577)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/331" adv="1" patch="1">331</ref>
      <ref source="BUGTRAQ" url="http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html" adv="1" patch="1">19980703 more about 'at'</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" prev="1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1410" seq="1999-1410" published="1997-05-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX" adv="1" patch="1">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420927&amp;w=2">19970509 Re: Irix: misc</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/330" adv="1" patch="1">330</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1411" seq="1999-1411" published="1998-11-26" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://lists.debian.org/debian-security-announce/debian-security-announce-1998/msg00033.html">19981126 new version of fsp fixes security flaw</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91228908407679&amp;w=2">19981128 Debian: Security flaw in FSP</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91244712808780&amp;w=2">19981130 Debian: Security flaw in FSP</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91936850009861&amp;w=2">19990217 Debian GNU/Linux 2.0r5 released (fwd)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7574.php">fsp-anon-ftp-access(7574)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/316" adv="1" patch="1">316</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1412" seq="1999-1412" published="1999-06-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14215" adv="1" patch="1">19990603 MacOS X system panic with CGI</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/306">306</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1413" seq="1999-1413" published="1996-08-03" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167419549&amp;w=2">19960803 Exploiting Zolaris 2.4 ??  :)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/296" adv="1" patch="1">296</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1414" seq="1999-1414" published="1999-05-25" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92765856706547&amp;w=2">19990525 Security Leak with IBM Netfinity Remote Control Software</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92902484317769&amp;w=2">19990609 IBM's response to "Security Leak with IBM Netfinity Remote Control Software</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/284">284</ref>
    </refs>
    <vuln_soft>
      <prod name="netfinity_remote_control" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1415" seq="1999-1415" published="1991-08-23" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-91.13.Ultrix.mail.vulnerability" adv="1" patch="1">CA-91.13</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/27">27</ref>
    </refs>
    <vuln_soft>
      <prod name="ultrix" vendor="digital">
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1416" seq="1999-1416" published="1998-08-23" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10383" adv="1">19980823 Solaris ab2 web server is junk</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/253">253</ref>
    </refs>
    <vuln_soft>
      <prod name="dwhttpd" vendor="inso">
        <vers num="3.1a4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1417" seq="1999-1417" published="1998-08-23" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10383" adv="1">19980823 Solaris ab2 web server is junk</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/253">253</ref>
    </refs>
    <vuln_soft>
      <prod name="answerbook2" vendor="inso">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1418" seq="1999-1418" published="1999-05-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13508" adv="1" patch="1">19990501 Update: security hole in the ICQ-Webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/246">246</ref>
    </refs>
    <vuln_soft>
      <prod name="icq_web_front" vendor="mirabilis">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1419" seq="1999-1419" published="1997-07-30" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/148" adv="1" patch="1">00148</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7535.php">sun-nisplus-bo(7535)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/219" adv="1" patch="1">219</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1420" seq="1999-1420" published="1998-07-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526016&amp;w=2">19980720 N-Base Vulnerability Advisory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526065&amp;w=2">19980722 N-Base Vulnerability Advisory Followup</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/212">212</ref>
    </refs>
    <vuln_soft>
      <prod name="nh2012" vendor="n-base">
        <vers num="2.53"/>
      </prod>
      <prod name="nh2012r" vendor="n-base">
        <vers num="2.53"/>
      </prod>
      <prod name="nh2015" vendor="n-base">
        <vers num="2.51"/>
      </prod>
      <prod name="nh2048" vendor="n-base">
        <vers num="1.33"/>
      </prod>
      <prod name="nh3012" vendor="n-base">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1421" seq="1999-1421" published="1998-07-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526016&amp;w=2">19980720 N-Base Vulnerability Advisory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526065&amp;w=2">19980722 N-Base Vulnerability Advisory Followup</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/212">212</ref>
    </refs>
    <vuln_soft>
      <prod name="nh208" vendor="n-base">
        <vers num=""/>
      </prod>
      <prod name="nh215" vendor="n-base">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1422" seq="1999-1422" published="1999-01-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91540043023167&amp;w=2">19990102 PATH variable in zip-slackware 2.0.35</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="2.0.35"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1423" seq="1999-1423" published="1997-06-26" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602558319160&amp;w=2">19970626 Solaris Ping bug (DoS)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602558319171&amp;w=2">19970627 SUMMARY: Solaris Ping bug (DoS)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602558319180&amp;w=2">19971005 Solaris Ping Bug and other [bc] oddities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602558319181&amp;w=2">19970627 Solaris Ping bug(inetsvc)</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/146" adv="1" patch="1">00146</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7492.php">ping-multicast-loopback-dos(7492)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/209" adv="1" patch="1">209</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1424" seq="1999-1424" published="1997-11-10" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" adv="1" patch="1">00145</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/208" adv="1" patch="1">208</ref>
    </refs>
    <vuln_soft>
      <prod name="solstice_adminsuite" vendor="sun">
        <vers num="2.1" edition=":x86"/>
        <vers num="2.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1425" seq="1999-1425" published="1997-11-10" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" adv="1" patch="1">00145</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/208" adv="1" patch="1">208</ref>
    </refs>
    <vuln_soft>
      <prod name="solstice_adminsuite" vendor="sun">
        <vers num="2.1" edition=":x86"/>
        <vers num="2.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1426" seq="1999-1426" published="1997-11-10" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" adv="1" patch="1">00145</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/208" adv="1" patch="1">208</ref>
    </refs>
    <vuln_soft>
      <prod name="solstice_adminsuite" vendor="sun">
        <vers num="2.1" edition=":x86"/>
        <vers num="2.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1427" seq="1999-1427" published="1997-11-10" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" adv="1" patch="1">00145</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/208" adv="1" patch="1">208</ref>
    </refs>
    <vuln_soft>
      <prod name="solstice_adminsuite" vendor="sun">
        <vers num="2.1" edition=":x86"/>
        <vers num="2.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1428" seq="1999-1428" published="1997-11-10" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145" adv="1" patch="1">00145</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/208" adv="1" patch="1">208</ref>
    </refs>
    <vuln_soft>
      <prod name="solstice_adminsuite" vendor="sun">
        <vers num="2.1" edition=":x86"/>
        <vers num="2.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1429" seq="1999-1429" published="1998-01-05" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88419633507543&amp;w=2">19980105 Security flaw in either DIT TransferPro or Solaris</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/204">204</ref>
    </refs>
    <vuln_soft>
      <prod name="transferpro" vendor="dit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1430" seq="1999-1430" published="1999-01-01" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91540043723185&amp;w=2">19990102 security problem with Royal daVinci</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/185">185</ref>
    </refs>
    <vuln_soft>
      <prod name="davinci" vendor="royal">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1431" seq="1999-1431" published="2005-01-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91576100022688&amp;w=2">19990107 WinNT, ZAK and Office 97</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91606260910008&amp;w=2">19990109 WinNT, ZAK and Office 97</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/181" adv="1">181</ref>
    </refs>
    <vuln_soft>
      <prod name="zero_administration_kit" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1432" seq="1999-1432" published="1998-07-16" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525997&amp;w=2">19980716 Security risk with powermanagemnet on Solaris 2.6</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/160">160</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1433" seq="1999-1433" published="1998-07-15" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525988&amp;w=2">19980715 JetAdmin software</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526067&amp;w=2">19980722 Re: JetAdmin software</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/157">157</ref>
    </refs>
    <vuln_soft>
      <prod name="jetadmin" vendor="hp">
        <vers num="rev._d.01.09"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1434" seq="1999-1434" published="1998-07-13" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525951&amp;w=2">19980713 Slackware Shadow Insecurity</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/155">155</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1435" seq="1999-1435" published="1998-07-10" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525933&amp;w=2">19980710 socks5 1.0r5 buffer overflow..</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/154">154</ref>
    </refs>
    <vuln_soft>
      <prod name="socks_5" vendor="nec">
        <vers num="1.0r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1436" seq="1999-1436" published="1998-07-08" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525905&amp;w=2">19980708 WWW Authorization Gateway</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/152">152</ref>
    </refs>
    <vuln_soft>
      <prod name="www_authorization_gateway" vendor="ray_chan">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1437" seq="1999-1437" published="1998-07-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525890&amp;w=2">19980707 ePerl: bad handling of ISINDEX queries</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104525927&amp;w=2">19980710 ePerl Security Update Available</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/151">151</ref>
    </refs>
    <vuln_soft>
      <prod name="eperl" vendor="ralf_s._engelschall">
        <vers num="2.2.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1438" seq="1999-1438" published="1991-02-22" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/105" adv="1" patch="1">00105</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-91.01a.SunOS.mail.vulnerability" adv="1" patch="1">CA-1991-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/15">15</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.0.3"/>
        <vers num="4.1"/>
        <vers num="4.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1439" seq="1999-1439" published="1998-01-02" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88419592307388&amp;w=2">19980102 Symlink bug with GCC 2.7.2</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88492937727193&amp;w=2">19980115 GCC 2.7.? /tmp files</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88524071002939&amp;w=2">19980108 GCC Exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/146">146</ref>
    </refs>
    <vuln_soft>
      <prod name="gcc" vendor="gcc">
        <vers num="2.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1440" seq="1999-1440" published="1999-01-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91522424302962&amp;w=2">19990101 Win32 ICQ 98a flaw</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/132">132</ref>
    </refs>
    <vuln_soft>
      <prod name="icq_98a" vendor="mirabilis">
        <vers num="1.30" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1441" seq="1999-1441" published="1998-06-30" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103126047&amp;w=2">19980630 Serious Linux 2.0.34 security problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/111">111</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1442" seq="1999-1442" published="1998-06-22" modified="2018-09-11" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html" adv="1">http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html</ref>
      <ref source="MISC" url="http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html" adv="1">http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/105" adv="1">105</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.20"/>
        <vers num="2.0.21"/>
        <vers num="2.0.22"/>
        <vers num="2.0.23"/>
        <vers num="2.0.24"/>
        <vers num="2.0.25"/>
        <vers num="2.0.26"/>
        <vers num="2.0.27"/>
        <vers num="2.0.28"/>
        <vers num="2.0.29"/>
        <vers num="2.0.30"/>
        <vers num="2.0.31"/>
        <vers num="2.0.32"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.0.39"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.1.12"/>
        <vers num="2.1.13"/>
        <vers num="2.1.14"/>
        <vers num="2.1.15"/>
        <vers num="2.1.16"/>
        <vers num="2.1.17"/>
        <vers num="2.1.18"/>
        <vers num="2.1.19"/>
        <vers num="2.1.20"/>
        <vers num="2.1.21"/>
        <vers num="2.1.22"/>
        <vers num="2.1.23"/>
        <vers num="2.1.24"/>
        <vers num="2.1.25"/>
        <vers num="2.1.26"/>
        <vers num="2.1.27"/>
        <vers num="2.1.28"/>
        <vers num="2.1.29"/>
        <vers num="2.1.30"/>
        <vers num="2.1.31"/>
        <vers num="2.1.32"/>
        <vers num="2.1.33"/>
        <vers num="2.1.34"/>
        <vers num="2.1.35"/>
        <vers num="2.1.36"/>
        <vers num="2.1.37"/>
        <vers num="2.1.38"/>
        <vers num="2.1.39"/>
        <vers num="2.1.40"/>
        <vers num="2.1.41"/>
        <vers num="2.1.42"/>
        <vers num="2.1.43"/>
        <vers num="2.1.44"/>
        <vers num="2.1.45"/>
        <vers num="2.1.46"/>
        <vers num="2.1.47"/>
        <vers num="2.1.48"/>
        <vers num="2.1.49"/>
        <vers num="2.1.50"/>
        <vers num="2.1.51"/>
        <vers num="2.1.52"/>
        <vers num="2.1.53"/>
        <vers num="2.1.54"/>
        <vers num="2.1.55"/>
        <vers num="2.1.56"/>
        <vers num="2.1.57"/>
        <vers num="2.1.58"/>
        <vers num="2.1.59"/>
        <vers num="2.1.60"/>
        <vers num="2.1.61"/>
        <vers num="2.1.62"/>
        <vers num="2.1.63"/>
        <vers num="2.1.64"/>
        <vers num="2.1.65"/>
        <vers num="2.1.66"/>
        <vers num="2.1.67"/>
        <vers num="2.1.68"/>
        <vers num="2.1.69"/>
        <vers num="2.1.70"/>
        <vers num="2.1.71"/>
        <vers num="2.1.72"/>
        <vers num="2.1.73"/>
        <vers num="2.1.74"/>
        <vers num="2.1.75"/>
        <vers num="2.1.76"/>
        <vers num="2.1.77"/>
        <vers num="2.1.78"/>
        <vers num="2.1.79"/>
        <vers num="2.1.80"/>
        <vers num="2.1.81"/>
        <vers num="2.1.82"/>
        <vers num="2.1.83"/>
        <vers num="2.1.84"/>
        <vers num="2.1.85"/>
        <vers num="2.1.86"/>
        <vers num="2.1.87"/>
        <vers num="2.1.88"/>
        <vers num="2.1.89"/>
        <vers num="2.1.90"/>
        <vers num="2.1.91"/>
        <vers num="2.1.92"/>
        <vers num="2.1.93"/>
        <vers num="2.1.94"/>
        <vers num="2.1.95"/>
        <vers num="2.1.96"/>
        <vers num="2.1.97"/>
        <vers num="2.1.98"/>
        <vers num="2.1.99"/>
        <vers num="2.1.100"/>
        <vers num="2.1.101"/>
        <vers num="2.1.102"/>
        <vers num="2.1.103"/>
        <vers num="2.1.104"/>
        <vers num="2.1.105"/>
        <vers num="2.1.106"/>
        <vers num="2.1.107"/>
        <vers num="2.1.108"/>
        <vers num="2.1.109"/>
        <vers num="2.1.110"/>
        <vers num="2.1.111"/>
        <vers num="2.1.112"/>
        <vers num="2.1.113"/>
        <vers num="2.1.114"/>
        <vers num="2.1.115"/>
        <vers num="2.1.116"/>
        <vers num="2.1.117"/>
        <vers num="2.1.118"/>
        <vers num="2.1.119"/>
        <vers num="2.1.120"/>
        <vers num="2.1.121"/>
        <vers num="2.1.122"/>
        <vers num="2.1.123"/>
        <vers num="2.1.124"/>
        <vers num="2.1.125"/>
        <vers num="2.1.126"/>
        <vers num="2.1.127"/>
        <vers num="2.1.128"/>
        <vers num="2.1.129"/>
        <vers num="2.1.130"/>
        <vers num="2.1.131"/>
        <vers num="2.1.132"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1443" seq="1999-1443" published="1998-06-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using &lt;CTRL>&lt;ALT>&lt;DEL> and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125869&amp;w=2">19980609 Full Armor</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221103125889&amp;w=2">19980602 Full Armor.... Fool Proof etc... bugs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/103">103</ref>
    </refs>
    <vuln_soft>
      <prod name="full_armor" vendor="micah_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1444" seq="1999-1444" published="1999-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://catless.ncl.ac.uk/Risks/20.41.html#subj4">http://catless.ncl.ac.uk/Risks/20.41.html#subj4</ref>
    </refs>
    <vuln_soft>
      <prod name="alibaba" vendor="computer_software_manufaktur">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1445" seq="1999-1445" published="1998-02-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=88637951600184&amp;w=2">19980202 imapd/ipop3d coredump in slackware 3.4</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1446" seq="1999-1446" published="1997-08-05" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=87602837719654&amp;w=2">19970805 Re: Strange behavior regarding directory</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=87602837719655&amp;w=2">19970806 Re: Strange behavior regarding directory</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1447" seq="1999-1447" published="1998-07-28" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526169&amp;w=2">19980728 Object tag crashes Internet Explorer 4.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526188&amp;w=2">19980730 Re: Object tag crashes Internet Explorer 4.0</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1448" seq="1999-1448" published="1998-07-29" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221104526168&amp;w=2">19980729 Eudora exploit (was Microsoft Security Bulletin (MS98-008))</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="3.05" prev="1"/>
      </prod>
      <prod name="eudora_light" vendor="qualcomm">
        <vers num="3.05" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1449" seq="1999-1449" published="1997-05-19" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://oamk.fi/~jukkao/bugtraq/before-971202/0498.html" adv="1">19970519 /dev/tcx0 crashes SunOS 4.1.4 on Sparc 20's</ref>
      <ref source="MISC" url="http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html" adv="1">http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1450" seq="1999-1450" published="1999-01-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.03b">SB-99.03b</ref>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.06b">SB-99.06b</ref>
      <ref source="SCO" url="ftp://ftp.sco.COM/SSE/sse020.ltr">SSE020</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5" prev="1"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1.3" prev="1"/>
        <vers num="7.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1451" seq="1999-1451" published="1999-12-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q231/3/68.asp" adv="1" patch="1">Q231368</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-013">MS99-013</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3271">iis-samples-winmsdp(3271)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1452" seq="1999-1452" published="1999-12-31" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91788829326419&amp;w=2">19990129 ole objects in a "secured" environment?</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91764169410814&amp;w=2">19990129 ole objects in a "secured" environment?</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91822011021558&amp;w=2">19990205 Alert: MS releases GINA-fix for SP3, SP4, and TS</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q214/8/02.asp" adv="1" patch="1">Q214802</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/198" adv="1" patch="1">198</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1975">nt-gina-clipboard(1975)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1453" seq="1999-1453" published="1999-02-02" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91979439932341&amp;w=2">19990222 New IE4 vulnerability : the clipboard again.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/215">215</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1454" seq="1999-1454" published="1999-10-04" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93915027622690&amp;w=2">19991004 Weakness In "The Matrix" Screensaver For Windows</ref>
    </refs>
    <vuln_soft>
      <prod name="matrix_screen_saver" vendor="macromedia">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1455" seq="1999-1455" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q158/3/20.asp" adv="1">Q158320</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7422">nt-rshsvc-ale-bypass(7422)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1456" seq="1999-1456" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.acme.com/software/thttpd/thttpd.html#releasenotes">http://www.acme.com/software/thttpd/thttpd.html#releasenotes</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10368" adv="1">19980819 thttpd 2.04 released (fwd)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1809">thttpd-file-read(1809)</ref>
    </refs>
    <vuln_soft>
      <prod name="thttpd_http_server" vendor="thttpd">
        <vers num="2.03" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1457" seq="1999-1457" published="1999-11-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html">19991116 thttpd</ref>
    </refs>
    <vuln_soft>
      <prod name="thttpd_http_server" vendor="thttpd">
        <vers num="1.90a"/>
        <vers num="2.04" prev="1"/>
        <vers num="2.04.31" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1458" seq="1999-1458" published="1999-01-25" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="http://ftp1.support.compaq.com/public/dunix/v4.0d/ssrt0583u.README" adv="1" patch="1">SSRT0583U</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121" adv="1" patch="1">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3138">du-at(3138)</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="4.0"/>
        <vers num="4.0a"/>
        <vers num="4.0b"/>
        <vers num="4.0c"/>
        <vers num="4.0d"/>
        <vers num="4.0e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1459" seq="1999-1459" published="1998-11-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/534" adv="1">534</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise10.php" adv="1" patch="1">19981102 BMC PATROL File Creation Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1388">bmc-patrol-file-create(1388)</ref>
    </refs>
    <vuln_soft>
      <prod name="patrol_agent" vendor="bmc">
        <vers num="3.2"/>
        <vers num="3.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1460" seq="1999-1460" published="1999-07-13" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93198293132463&amp;w=2">19990713 Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93372579004129&amp;w=2">19990801 Re: Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/525" adv="1" patch="1">525</ref>
    </refs>
    <vuln_soft>
      <prod name="patrol_agent" vendor="bmc">
        <vers num="3.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.5"/>
        <vers num="3.2.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1461" seq="1999-1461" published="1997-05-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I" adv="1" patch="1">20001101-01-I</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420921&amp;w=2">19970507 Irix: misc</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/381" adv="1" patch="1">381</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.3"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1462" seq="1999-1462" published="1999-12-31" modified="2018-11-29" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attackers to read portions of arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13440" adv="1">19990426 FW: Security Notice: Big Brother 1.09b/c</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/142" adv="1" patch="1">142</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3755" adv="1">http-cgi-bigbrother-bbhist(3755)</ref>
    </refs>
    <vuln_soft>
      <prod name="big_brother" vendor="bb4">
        <vers num="1.09b"/>
        <vers num="1.09c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1463" seq="1999-1463" published="1997-07-10" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7219" adv="1" patch="1">19970710 A New Fragmentation Attack</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/528">nt-frag(528)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1464" seq="1999-1464" published="1999-12-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml" adv="1" patch="1">J-016</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml" adv="1" patch="1">19981105 Cisco IOS DFS Access List Leakage</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1401">cisco-acl-leakage(1401)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.1cc"/>
        <vers num="11.1ct"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1465" seq="1999-1465" published="1999-12-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml" adv="1" patch="1">J-016</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml" adv="1" patch="1">19981105 Cisco IOS DFS Access List Leakage</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1401">cisco-acl-leakage(1401)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1466" seq="1999-1466" published="1992-12-10" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-20.html" adv="1" patch="1">CA-1992-20</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/53" adv="1" patch="1">53</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="8.2"/>
        <vers num="8.3"/>
        <vers num="9.0"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1467" seq="1999-1467" published="1989-10-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1989-07.html" adv="1" patch="1">CA-1989-07</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5" adv="1" patch="1">5</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3165">sun-rcp(3165)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1468" seq="1999-1468" published="1991-10-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability" adv="1" patch="1">CA-91.20</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7160.php">rdist-popen-gain-privileges(7160)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/31" adv="1" patch="1">31</ref>
    </refs>
    <vuln_soft>
      <prod name="next" vendor="next">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="unicos" vendor="cray">
        <vers num="6.0"/>
        <vers num="6.0e"/>
        <vers num="6.1"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="4.0"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.0.3"/>
        <vers num="4.0.3c"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1psr_a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1469" seq="1999-1469" published="1999-09-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93871926821410&amp;w=2">19990930 mini-sql Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="w3-auth" vendor="hughes_technologies">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1470" seq="1999-1470" published="1999-06-24" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93034788412494&amp;w=2">19990624 Eastman Software Work Management 3.21</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/485" adv="1">485</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2303">eastman-cleartext-passwords(2303)</ref>
    </refs>
    <vuln_soft>
      <prod name="work_management" vendor="eastman_software">
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1471" seq="1999-1471" published="1989-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1989-01.html" adv="1" patch="1">CA-1989-01</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7152.php">bsd-passwd-bo(7152)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/4" adv="1" patch="1">4</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd" vendor="bsd">
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1472" seq="1999-1472" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87710897923098&amp;w=2">19971017 Security Hole in Explorer 4.0</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp" adv="1" patch="1">Q176697</ref>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/7/94.asp" adv="1" patch="1">Q176794</ref>
      <ref source="MISC" url="http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html" adv="1" patch="1">http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html</ref>
      <ref source="CONFIRM" url="http://www.microsoft.com/Windows/ie/security/freiburg.asp">http://www.microsoft.com/Windows/ie/security/freiburg.asp</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/587">http-ie-spy(587)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1473" seq="1999-1473" published="1999-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp" adv="1" patch="1">Q176697</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7426.php">ie-page-redirect(7426)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0.2"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1474" seq="1999-1474" published="1999-12-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.microsoft.com/windows/ie/security/powerpoint.asp">http://www.microsoft.com/windows/ie/security/powerpoint.asp</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/179">nt-ppt-patch(179)</ref>
    </refs>
    <vuln_soft>
      <prod name="powerpoint" vendor="microsoft">
        <vers num="95"/>
        <vers num="97"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1475" seq="1999-1475" published="1999-11-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/35483" adv="1" patch="1">19991119 ProFTPd - mod_sqlpw.c</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/812" adv="1" patch="1">812</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1476" seq="1999-1476" published="1999-12-31" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the "Invalid Operand with Locked CMPXCHG8B Instruction" problem.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/52.asp" adv="1" patch="1">Q163852</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/704">pentium-crash(704)</ref>
    </refs>
    <vuln_soft>
      <prod name="pentium" vendor="intel">
        <vers num="" edition=":mmx"/>
      </prod>
      <prod name="pentuim" vendor="intel">
        <vers num="" edition=":overdrive"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1477" seq="1999-1477" published="1999-09-23" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28717" adv="1">19990923 Linux GNOME exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/663" adv="1" patch="1">663</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3349">gnome-espeaker-local-bo(3349)</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome_libs" vendor="gnome">
        <vers num="1.0.8"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1478" seq="1999-1478" published="1999-07-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93138827429589&amp;w=2">19990706 Bug in SUN's Hotspot VM</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93240220324183&amp;w=2">19990716 FW: (Review ID: 85125) Hotspot crashes bringing down webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/522">522</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2348">sun-hotspot-vm(2348)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1479" seq="1999-1479" published="1998-06-24" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9609">19980624 textcounter.pl SECURITY HOLE</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2265">2265</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2052">http-cgi-textcounter(2052)</ref>
    </refs>
    <vuln_soft>
      <prod name="textcounter" vendor="matt_wright">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1480" seq="1999-1480" published="1998-06-11" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/429" adv="1" patch="1">429</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1481" seq="1999-1481" published="1999-12-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991103 [squid]exploit for external authentication problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/741" adv="1" patch="1">741</ref>
      <ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.2/bugs/" adv="1" patch="1">http://www.squid-cache.org/Versions/v2/2.2/bugs/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3433">squid-proxy-auth-access(3433)</ref>
    </refs>
    <vuln_soft>
      <prod name="squid_web_proxy" vendor="national_science_foundation">
        <vers num="1.0"/>
        <vers num="1.0novm"/>
        <vers num="1.1"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1482" seq="1999-1482" published="1999-02-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-02-15&amp;msg=Pine.LNX.3.96.990219175605.9622A-100000@ferret.lmh.ox.ac.uk" patch="1">19990219 Security hole: "zgv"</ref>
    </refs>
    <vuln_soft>
      <prod name="zgv" vendor="svgalib">
        <vers num="3.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1483" seq="1999-1483" published="1997-06-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7041" adv="1">19970619 svgalib/zgv</ref>
    </refs>
    <vuln_soft>
      <prod name="svgalib" vendor="svgalib">
        <vers num="1.2.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1484" seq="1999-1484" published="1999-09-24" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719" adv="1" patch="1">19990924 Several ActiveX Buffer Overruns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/668" adv="1" patch="1">668</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3310">msn-setup-bbs-activex-bo(3310)</ref>
    </refs>
    <vuln_soft>
      <prod name="msn_setup_bulletin_board_services" vendor="microsoft">
        <vers num="4.71.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1485" seq="1999-1485" published="1999-05-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92818552106912&amp;w=2">19990531 IRIX 6.5 nsd virtual filesystem vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/412">412</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2246">sgi-nsd-view(2246)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2247">sgi-nsd-create(2247)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1486" seq="1999-1486" published="1998-02-25" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info">http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/408" adv="1" patch="1">408</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX75554&amp;apar=only">IX75554</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76330&amp;apar=only">IX76330</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76853&amp;apar=only">IX76853</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7675">aix-sadc-timex(7675)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1487" seq="1999-1487" published="1998-01-21" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7477.php">aix-digest(7477)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/405" adv="1" patch="1">405</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/servlet/support/manager?rt=0&amp;rs=0&amp;org=apars&amp;doc=41D8B61D1E1C4FAB852567C9002C546C" adv="1">IX74599</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1488" seq="1999-1488" published="1999-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-079a.shtml" adv="1" patch="1">I-079A</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7217.php">ibm-sdr-read-files(7217)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/371" adv="1" patch="1">371</ref>
    </refs>
    <vuln_soft>
      <prod name="system_data_repository" vendor="ibm">
        <vers num="sp_2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1489" seq="1999-1489" published="1997-03-04" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/6384" adv="1">19970304 Linux SuperProbe exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/364" adv="1" patch="1">364</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1490" seq="1999-1490" published="1998-05-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101926021&amp;w=2">19980528 ALERT: Tiresome security hole in "xosview", RedHat5.1?</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101926034&amp;w=2">19980529 Re: Tiresome security hole in "xosview" (xosexp.c)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8787.php">linux-xosview-bo(8787)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/362" adv="1" patch="1">362</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1491" seq="1999-1491" published="1996-02-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167418994&amp;w=2">19960202 abuse Red Hat 2.1 security hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/354" adv="1" patch="1">354</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1492" seq="1999-1492" published="1998-05-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030" adv="1" patch="1">19980502-01-P3030</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/348" adv="1" patch="1">348</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2103">sgi-diskperf(2103)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2104">sgi-diskalign(2104)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1493" seq="1999-1493" published="1991-12-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1991-23.html" adv="1" patch="1">CA-1991-23</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/34">34</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7158">apollo-crp-root-access(7158)</ref>
    </refs>
    <vuln_soft>
      <prod name="apollo_domain_os" vendor="hp">
        <vers num="sr10.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1494" seq="1999-1494" published="1994-08-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P" adv="1" patch="1">19950209-00-P</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/675" adv="1">19940809 Re: IRIX 5.2 Security Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/336" adv="1" patch="1">336</ref>
      <ref source="BUGTRAQ" url="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html" adv="1" patch="1">19950307 sigh. another Irix 5.2 hole.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2112">sgi-colorview(2112)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1495" seq="1999-1495" published="1999-02-18" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12580">19990218 xtvscreen and suse 6</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/325" adv="1">325</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1792">xtvscreen-overwrite(1792)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1496" seq="1999-1496" published="1999-06-08" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14665" adv="1">19990608 unneeded information in sudo</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/321" adv="1">321</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2277">sudo-file-exists(2277)</ref>
    </refs>
    <vuln_soft>
      <prod name="sudo" vendor="todd_miller">
        <vers num="1.5"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1497" seq="1999-1497" published="1999-12-21" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39329" adv="1">19991221 [w00giving '99 #11] IMail's password encryption scheme</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/880" adv="1">880</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1498" seq="1999-1498" published="1998-04-06" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/82" adv="1">82</ref>
    </refs>
    <vuln_soft>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1499" seq="1999-1499" published="1998-04-10" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8966" adv="1">19980410 BIND 4.9.7 named follows symlinks, clobbers anything</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/80" adv="1" patch="1">80</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="4.9"/>
        <vers num="8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1500" seq="1999-1500" published="1999-10-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Internet Anywhere POP3 Mail Server 2.3.1 allows remote attackers to cause a denial of service (crash) via (1) LIST, (2) TOP, or (3) UIDL commands using letters as arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93880357530599&amp;w=2">19991001 Vulnerabilities in the Internet Anywhere Mail Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/733" adv="1" patch="1">733</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_anywhere_mail_server" vendor="true_north">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1501" seq="1999-1501" published="1998-04-08" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89217373930054&amp;w=2">19980408 SGI O2 ipx security issue</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/70" adv="1" patch="1">70</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/71" adv="1" patch="1">71</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1502" seq="1999-1502" published="1998-04-08" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89205623028934&amp;w=2">19980408 QuakeI client: serious holes.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/68" adv="1">68</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/69" adv="1">69</ref>
    </refs>
    <vuln_soft>
      <prod name="quake" vendor="id_software">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1503" seq="1999-1503" published="1998-04-08" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Network Flight Recorder (NFR) 1.5 and 1.6 allows remote attackers to cause a denial of service in nfrd (crash) via a TCP packet with a null header and data field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/63" adv="1" patch="1">63</ref>
    </refs>
    <vuln_soft>
      <prod name="nfr" vendor="nfr">
        <vers num="1.5"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1504" seq="1999-1504" published="1998-04-08" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8951" adv="1">19980408 Re: AppleShare IP Mail Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/62" adv="1">62</ref>
    </refs>
    <vuln_soft>
      <prod name="stalker_internet_mail_server" vendor="stalker">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1505" seq="1999-1505" published="1998-04-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=89200537415923&amp;w=2">19980407 QW vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/60" adv="1">60</ref>
    </refs>
    <vuln_soft>
      <prod name="quakeworld" vendor="id_software">
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1506" seq="1999-1506" published="1990-01-29" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-90.01.sun.sendmail.vulnerability" adv="1">CA-1990-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6" adv="1" patch="1">6</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1507" seq="1999-1507" published="1993-02-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-03.html" adv="1" patch="1">CA-1993-03</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/59" adv="1" patch="1">59</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/521">sun-dir(521)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1psr_a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1508" seq="1999-1508" published="1999-11-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94286041430870&amp;w=2">19991116 [Fwd: Printer Vulnerability: Tektronix PhaserLink Webserver gives Administrator Password]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/806" adv="1" patch="1">806</ref>
    </refs>
    <vuln_soft>
      <prod name="phaser_network_printer_740" vendor="tek">
        <vers num=""/>
      </prod>
      <prod name="phaser_network_printer_750" vendor="tek">
        <vers num=""/>
      </prod>
      <prod name="phaser_network_printer_750dp" vendor="tek">
        <vers num=""/>
      </prod>
      <prod name="phaser_network_printer_840" vendor="tek">
        <vers num=""/>
      </prod>
      <prod name="phaser_network_printer_930" vendor="tek">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1509" seq="1999-1509" published="1999-11-04" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94183041514522&amp;w=2">19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94177470915423&amp;w=2">19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/773" adv="1" patch="1">773</ref>
    </refs>
    <vuln_soft>
      <prod name="eserv" vendor="etype">
        <vers num="2.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1510" seq="1999-1510" published="1999-05-17" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=92697301706956&amp;w=2">19990517 Vulnerabilities in BisonWare FTP Server 3.5</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3234">bisonware-command-bo(3234)</ref>
    </refs>
    <vuln_soft>
      <prod name="bisonware_ftp_server" vendor="bisonware">
        <vers num="4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1511" seq="1999-1511" published="1999-11-10" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94226003804744&amp;w=2">19991110 Multiples Remotes DoS Attacks in Artisoft XtraMail v1.11 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/791" adv="1">791</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3488">xtramail-pass-dos(3488)</ref>
    </refs>
    <vuln_soft>
      <prod name="xtramail" vendor="artisoft">
        <vers num="1.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1512" seq="1999-1512" published="1999-12-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93219846414732&amp;w=2">19990716 AMaViS virus scanner for Linux - root exploit</ref>
      <ref source="CONFIRM" url="http://www.amavis.org/ChangeLog.txt" adv="1">http://www.amavis.org/ChangeLog.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/527" adv="1" patch="1">527</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2349">amavis-command-execute(2349)</ref>
    </refs>
    <vuln_soft>
      <prod name="virus_scanner" vendor="amavis">
        <vers num="0.2_pre4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1513" seq="1999-1513" published="1999-08-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93616983223090&amp;w=2">19990830 One more 3Com SNMP vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="superstack_ii_hub" vendor="3com">
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1514" seq="1999-1514" published="2001-11-28" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94121377716133&amp;w=2">19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94130292519646&amp;w=2">19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/749" adv="1">749</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3401">expressfs-command-bo(3401)</ref>
    </refs>
    <vuln_soft>
      <prod name="expressfs" vendor="celtech_software">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1515" seq="1999-1515" published="1999-08-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/613" adv="1" patch="1">613</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3290">tfs-gateway-dos(3290)</ref>
    </refs>
    <vuln_soft>
      <prod name="tfs_gateway" vendor="tenfour">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1516" seq="1999-1516" published="1999-09-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93677241318492&amp;w=2">19990902 [SECURITY] TenFour TFS SMTP 3.2 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="tfs_gateway_smtp" vendor="tenfour">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1517" seq="1999-1517" published="1999-11-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94148942818975&amp;w=2">19991101 Amanda multiple vendor local root compromises</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/750" adv="1" patch="1">750</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1518" seq="1999-1518" published="1999-07-15" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93207728118694&amp;w=2">19990715 Shared memory DoS's</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/526" adv="1" patch="1">526</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2351">bsd-shared-memory-dos(2351)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1519" seq="1999-1519" published="1999-11-17" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94286244700573&amp;w=2">19991117 Remote D.o.S Attack in G6 FTP Server v2.0 (beta 4/5) Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/805" adv="1">805</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3513">g6ftp-username-dos(3513)</ref>
    </refs>
    <vuln_soft>
      <prod name="g6_ftp_server" vendor="gene6">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1520" seq="1999-1520" published="1999-05-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92647407227303&amp;w=2">19990511 [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/256" adv="1" patch="1">256</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2270">siteserver-site-csc(2270)</ref>
    </refs>
    <vuln_soft>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1521" seq="1999-1521" published="1999-09-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93720402717560&amp;w=2">19990912 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94121824921783&amp;w=2">19990729 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/633" adv="1">633</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2240">cmail-command-bo(2240)</ref>
    </refs>
    <vuln_soft>
      <prod name="cmail" vendor="computalynx">
        <vers num="2.3sp2"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1522" seq="1999-1522" published="1999-10-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93942579008408&amp;w=2">19991007 Roxen security alert</ref>
    </refs>
    <vuln_soft>
      <prod name="roxen_web_server" vendor="roxen">
        <vers num="1.3.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1523" seq="1999-1523" published="1999-10-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93901161727373&amp;w=2">19991004</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93941351229256&amp;w=2">19991006 Re: Sample DOS against the Sambar HTTP-Server</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1672">sambar-logging-bo(1672)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1524" seq="1999-1524" published="1999-08-07" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93424680430460&amp;w=2">19990807 Re: FlowPoint DSL router vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="flowpoint_dsl_router" vendor="flowpoint">
        <vers num="3.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1525" seq="1999-1525" published="1997-03-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=87602167420670&amp;w=2">19970314 Shockwave Security Alert</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1585">shockwave-internal-access(1585)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1586">shockwave-file-read-vuln(1586)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/460">http-ns-shockwave(460)</ref>
    </refs>
    <vuln_soft>
      <prod name="shockwave_flash_plugin" vendor="macromedia">
        <vers num="6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1526" seq="1999-1526" published="1999-03-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12842" adv="1">19990311 [Fwd: Shockwave 7 Security Hole]</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1931">shockwave-updater(1931)</ref>
    </refs>
    <vuln_soft>
      <prod name="shockwave_flash_plugin" vendor="macromedia">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1527" seq="1999-1527" published="1999-11-23" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94338883114254&amp;w=2">19991123 NetBeans/ Forte' Java IDE HTTP vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/816" adv="1" patch="1">816</ref>
    </refs>
    <vuln_soft>
      <prod name="forte" vendor="sun">
        <vers num="community_1.0_beta"/>
      </prod>
      <prod name="netbeans_developer" vendor="sun">
        <vers num="3.0_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1528" seq="1999-1528" published="1999-11-14" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94261444428430&amp;w=2">19991114 MacOS 9 and the MacOS Netware Client</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/794" adv="1" patch="1">794</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_client" vendor="prosoft_engineering">
        <vers num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1529" seq="1999-1529" published="1999-11-07" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94201512111092&amp;w=2">19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94204166130782&amp;w=2">19991108 Patch for VirusWall 3.23.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94210427406568&amp;w=2">19991108 Re: Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94199707625818&amp;w=2">19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94208143007829&amp;w=2">19991108 Patch for VirusWall 3.23.</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/55551" adv="1">20000417 New DOS on Interscan NT/3.32</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/787" adv="1" patch="1">787</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3465">viruswall-helo-bo(3465)</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.3"/>
        <vers num="3.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1530" seq="1999-1530" published="1999-11-08" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94209954200450&amp;w=2">19991108 Security flaw in Cobalt RaQ2 cgiwrap</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94225629200045&amp;w=2">19991109 [Cobalt] Security Advisory - cgiwrap</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7764.php">cobalt-cgiwrap-incorrect-permissions(7764)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/777" adv="1" patch="1">777</ref>
    </refs>
    <vuln_soft>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1531" seq="1999-1531" published="1999-11-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7767.php">ibm-homepageprint-bo(7767)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/763" adv="1" patch="1">763</ref>
    </refs>
    <vuln_soft>
      <prod name="homepageprint" vendor="ibm">
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1532" seq="1999-1532" published="1999-10-29" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94117465014255&amp;w=2">19991029 message:Netscape Messaging Server RCPT TO vul.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/748" adv="1">748</ref>
    </refs>
    <vuln_soft>
      <prod name="messaging_server" vendor="netscape">
        <vers num="3.6"/>
        <vers num="3.54"/>
        <vers num="3.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1533" seq="1999-1533" published="1999-11-07" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93846522511387&amp;w=2">19990926 DoS Exploit in Eicon Diehl LAN ISDN Modem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/665">665</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3317">diva-lan-isdn-dos(3317)</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.2.3"/>
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1534" seq="1999-1534" published="1999-09-23" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93837184228248&amp;w=2">19990923 Multiple vendor Knox Arkiea local root/remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/661" adv="1" patch="1">661</ref>
    </refs>
    <vuln_soft>
      <prod name="arkeia" vendor="knox_software">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1535" seq="1999-1535" published="1999-07-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93256878011447&amp;w=2">19990720 Buffer overflow in AspUpload 1.4</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93501427820328&amp;w=2">19990818 AspUpload Buffer Overflow Fixed</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/592" adv="1">592</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3291">http-aspupload-bo(3291)</ref>
    </refs>
    <vuln_soft>
      <prod name="aspupload" vendor="persits">
        <vers num="1.4.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1536" seq="1999-1536" published="1999-07-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93347785827287&amp;w=2">19990730 World writable root owned script in SalesBuilder (RedHat 6.0)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/560" adv="1">560</ref>
    </refs>
    <vuln_soft>
      <prod name="salesbuilder" vendor="acushop">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1537" seq="1999-1537" published="1999-07-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=93138827329577&amp;w=2">19990707 SSL and IIS.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/521" adv="1" patch="1">521</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2352">ssl-iis-dos(2352)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1538" seq="1999-1538" published="1999-01-14" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91638375309890&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=91632724913080&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/189">189</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1539" seq="1999-1539" published="1999-11-10" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94225924803704&amp;w=2">19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94223972910670&amp;w=2">19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/796" adv="1">796</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3491">qvtterm-login-dos(3491)</ref>
    </refs>
    <vuln_soft>
      <prod name="qvt_net" vendor="qpc_software">
        <vers num="4.3"/>
      </prod>
      <prod name="qvt_term_plus" vendor="qpc_software">
        <vers num="4.2d"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1540" seq="1999-1540" published="1999-10-04" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93916168802365&amp;w=2">19991005 Cactus Software's shell-lock</ref>
      <ref source="L0PHT" url="http://www.atstake.com/research/advisories/1999/shell-lock.txt">19991004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3356">cactus-shell-lock-retrieve-shell-code(3356)</ref>
    </refs>
    <vuln_soft>
      <prod name="shell-lock" vendor="cactus_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1541" seq="1999-1541" published="1999-10-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">shell-lock in Cactus Software Shell Lock allows local users to read or modify decoded shell files before they are executed, via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93916168802365&amp;w=2">19991005 Cactus Software's shell-lock</ref>
      <ref source="L0PHT" url="http://www.atstake.com/research/advisories/1999/shell-lock.txt">19991004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3358">cactus-shell-lock-root-privs(3358)</ref>
    </refs>
    <vuln_soft>
      <prod name="shell-lock" vendor="cactus_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1542" seq="1999-1542" published="1999-10-04" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93915641729415&amp;w=2">19991004 RH6.0 local/remote command execution</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93923853105687&amp;w=2">19991006 Fwd: [Re: RH6.0 local/remote command execution]</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3353">linux-rh-rpmmail(3353)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1543" seq="1999-1543" published="1999-07-10" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MacOS uses weak encryption for passwords that are stored in the Users &amp; Groups Data File.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93188174906513&amp;w=2">19990710 MacOS system encryption algorithm</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93736667813924&amp;w=2">19990914 MacOS system encryption algorithm 3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/519" adv="1" patch="1">519</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num="7.5.3"/>
        <vers num="7.6"/>
        <vers num="7.6.1"/>
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="8.5"/>
        <vers num="8.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1544" seq="1999-1544" published="1999-01-24" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91722115016183&amp;w=2">19990124 Advisory: IIS FTP Exploit/DoS Attack</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1545" seq="1999-1545" published="1999-07-14" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93216103027827&amp;w=2">19990714</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93226771401036&amp;w=2">19990717 joe 2.8 makes world-readable DEADJOE</ref>
    </refs>
    <vuln_soft>
      <prod name="joe" vendor="joes_own_editor">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1546" seq="1999-1546" published="1999-01-29" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12217">19990129 TROJAN: netstation.navio-comm.rte 1.1.0.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1724">navionc-config-script(1724)</ref>
    </refs>
    <vuln_soft>
      <prod name="navio_nc_browser" vendor="ibm">
        <vers num="1.1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1547" seq="1999-1547" published="1999-11-25" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94359982417686&amp;w=2">19991125 Oracle Web Listener</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94390053530890&amp;w=2">19991125 Oracle Web Listener</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/841" adv="1">841</ref>
    </refs>
    <vuln_soft>
      <prod name="web_listener" vendor="oracle">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1548" seq="1999-1548" published="1999-11-24" modified="2017-02-15" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_Cabletron.html" adv="1" patch="1">19991124 Cabletron SmartSwitch Router 8000 Firmware v2.x</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/821">821</ref>
    </refs>
    <vuln_soft>
      <prod name="smartswitch_router_8000_firmware" vendor="cabletron">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1549" seq="1999-1549" published="1999-11-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94286509804526&amp;w=2">19991116 lynx 2.8.x - 'special URLs' anti-spoofing protection is weak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/804" adv="1">804</ref>
    </refs>
    <vuln_soft>
      <prod name="lynx" vendor="university_of_kansas">
        <vers num="2.7"/>
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1550" seq="1999-1550" published="1999-11-08" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94217006208374&amp;w=2">19991108 BigIP - bigconf.cgi holes</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94217879020184&amp;w=2">19991109 Re: BigIP - bigconf.cgi holes</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94225879703021&amp;w=2">19991109</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7771.php">bigip-bigconf-view-files(7771)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/778" adv="1">778</ref>
    </refs>
    <vuln_soft>
      <prod name="tmos" vendor="f5">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1551" seq="1999-1551" published="1999-03-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990302 Multiple IMail Vulnerabilites</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/505" patch="1">505</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1898">imail-websvc-overflow(1898)</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1552" seq="1999-1552" published="1994-07-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://lists.insecure.org/lists/bugtraq/1994/Jul/0038.html">19940720 xnews and XDM</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/358" adv="1" patch="1">358</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1553" seq="1999-1553" published="1999-05-01" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.</descript>
    </desc>
    <sols>
      <sol source="nvd">The authors were notified of this problem and it was fixed in devel-release 0.99.7.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12730">19990301 [0z0n3] XCmail remotely exploitable vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/311">311</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1859">xcmail-reply-overflow(1859)</ref>
    </refs>
    <vuln_soft>
      <prod name="xcmail" vendor="xcmail">
        <vers num="0.99.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1554" seq="1999-1554" published="1990-10-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1990-08.html" adv="1" patch="1">CA-1990-08</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/3164.php">sgi-irix-reset(3164)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/13" adv="1" patch="1">13</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="3.3"/>
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1555" seq="1999-1555" published="1998-06-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan's antivirus update feature to install a Trojan horse dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9515" adv="1" patch="1">19980611 Cheyenne Inoculan vulnerability on NT</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/106">106</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1536">inoculan-bad-permissions(1536)</ref>
    </refs>
    <vuln_soft>
      <prod name="inoculan_anti-virus_server" vendor="cheyenne">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1556" seq="1999-1556" published="1998-06-29" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=90222453431645&amp;w=2">19980629 MS SQL Server 6.5 stores password in unprotected registry keys</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/109" adv="1">109</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7354">mssql-sqlexecutivecmdexec-password(7354)</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1557" seq="1999-1557" published="2005-05-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990301 Multiple IMail Vulnerabilites</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1895">imail-imap-overflow(1895)</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1558" seq="1999-1558" published="1998-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-071a.shtml" adv="1" patch="1">I-071A</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7151.php">openvms-loginout-unauth-access(7151)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/161" adv="1" patch="1">161</ref>
    </refs>
    <vuln_soft>
      <prod name="digital_openvms" vendor="digital">
        <vers num="7.1"/>
      </prod>
      <prod name="digital_openvms_axp" vendor="digital">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1559" seq="1999-1559" published="1999-03-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92299263017061&amp;w=2">19990331 Xylan OmniSwitch "features"</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2064">xylan-omniswitch-login(2064)</ref>
    </refs>
    <vuln_soft>
      <prod name="omniswitch" vendor="alcatel">
        <vers num="3.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1560" seq="1999-1560" published="1999-07-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in a script in Texas A&amp;M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93252050203589&amp;w=2">19990720 tiger vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2369">tiger-script-execute(2369)</ref>
    </refs>
    <vuln_soft>
      <prod name="tiger" vendor="tamu">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1561" seq="1999-1561" published="1999-08-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/24852" adv="1" patch="1">19990820 Winamp SHOUTcast server: Gain Administrator Password</ref>
    </refs>
    <vuln_soft>
      <prod name="shoutcast_server" vendor="nullsoft">
        <vers num="1.9.7" edition=":win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1562" seq="1999-1562" published="1999-09-05" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-084">DSA-084</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/26915" adv="1" patch="1">19990905 gftp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3446">3446</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_client" vendor="gftp">
        <vers num="1.13"/>
        <vers num="2.0.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1563" seq="1999-1563" published="2000-10-14" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/30849" adv="1">19991014 NEUROCOM: Nashuatec printer, 3 vulnerabilities found</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/35075" adv="1">19991116 NEUROCOM: Nashuatec D445/435 vulnerabilities updated</ref>
    </refs>
    <vuln_soft>
      <prod name="d435" vendor="nachuatec">
        <vers num=""/>
      </prod>
      <prod name="d445" vendor="nachuatec">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1564" seq="1999-1564" published="1999-09-02" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/26166" adv="1">19990902 [ Kernel panic with FreeBSD-3.2-19990830-STABLE ]</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1565" seq="1999-1565" published="1999-08-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/24784" adv="1" patch="1">19990820 [SECURITY] New versions of man2html fixes postinst glitch</ref>
    </refs>
    <vuln_soft>
      <prod name="man2html" vendor="earl_hood">
        <vers num="2.1" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1566" seq="1999-1566" published="1999-05-08" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13600" adv="1">19990508 iParty Daemon Vulnerability w/ Exploit Code (worse than thought?)</ref>
    </refs>
    <vuln_soft>
      <prod name="iparty" vendor="intel">
        <vers num="1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1567" seq="1999-1567" published="1999-03-08" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1948">testtrack-dos(1948)</ref>
    </refs>
    <vuln_soft>
      <prod name="testtrack" vendor="seapine_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1568" seq="1999-1568" published="1999-01-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91981352617720&amp;w=2">19990223 NcFTPd remote buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12699">19990223 Comments on NcFTPd "theoretical root compromise"</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/1833">ncftpd-port-bo(1833)</ref>
    </refs>
    <vuln_soft>
      <prod name="ncftpd_ftp_server" vendor="ncftpd">
        <vers num="2.4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1569" seq="1999-1569" published="2001-07-17" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=90221101925989&amp;w=2">19980502 NetQuake Protocol problem resulting in smurf like effect.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91012172524181&amp;w=2">19981101 Quake problem?</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197268">20010716 Quake client and server denial-of-service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3051" adv="1">3051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6871">quake-spoofed-client-dos(6871)</ref>
    </refs>
    <vuln_soft>
      <prod name="quake" vendor="id_software">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1570" seq="1999-1570" published="2002-05-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in sar for OpenServer 5.0.5 allows local users to gain root privileges via a long -o parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.17/CSSA-2002-SCO.17.txt" adv="1" patch="1">CSSA-2002-SCO.17</ref>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=102098949103708&amp;w=2">20020509 Sar -o exploitation process info.</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/27074">19990909 19 SCO 5.0.5+Skunware98 buffer overflows</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8989.php" adv="1" patch="1">openserver-sar-bo(8989)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/4089" adv="1" patch="1">4089</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="caldera">
        <vers num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1571" seq="1999-1571" published="1999-11-04" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a different vulnerability than CVE-1999-1570.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://stage.caldera.com/pub/security/sse/security_bulletins/SB-99.17c">SB-99.17c</ref>
      <ref source="CONFIRM" url="ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr">ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93762097815861&amp;w=2">19990917 Re: recent SCO 5.0.x vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94053017801639&amp;w=2">19991020 Re: recent SCO 5.0.x vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94183363719024&amp;w=2">19991105 SCO Security Bulletin 99.17</ref>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=102098949103708&amp;w=2">20020509 Sar -o exploitation process info.</ref>
      <ref source="MISC" url="http://online.securityfocus.com/advisories/1843" adv="1" patch="1">http://online.securityfocus.com/advisories/1843</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/27074">19990909 19 SCO 5.0.5+Skunware98 buffer overflows</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8989.php" adv="1">openserver-sar-bo(8989)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/643">643</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.0"/>
        <vers num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1572" seq="1999-1572" published="1996-07-16" modified="2017-10-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in rev 1.3 of cpio/main.c.</sol>
    </sols>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=110763404701519&amp;w=2">20050204 [USN-75-1] cpio vulnerability</ref>
      <ref source="CONFIRM" url="http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf">http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-664">DSA-664</ref>
      <ref source="MISC" url="http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391">http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:032">MDKSA-2005:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-073.html">RHSA-2005:073</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-080.html">RHSA-2005:080</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-806.html">RHSA-2005:806</ref>
      <ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/19167">cpio-o-archive-insecure-permissions(19167)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10888">oval:org.mitre.oval:def:10888</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="3.0"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.1.0"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="9.2"/>
        <vers num="10.0"/>
        <vers num="10.1"/>
        <vers num="cs2.1"/>
        <vers num="cs3.0"/>
      </prod>
      <prod name="enterprise_linux" vendor="redhat">
        <vers num="4.0" edition=":advanced_server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":workstation"/>
      </prod>
      <prod name="enterprise_linux_desktop" vendor="redhat">
        <vers num="4.0"/>
      </prod>
      <prod name="ubuntu_linux" vendor="ubuntu">
        <vers num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1573" seq="1999-1573" published="1999-12-28" modified="2017-10-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=490" patch="1">ESB-98.186</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-022.shtml" patch="1">J-022</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/13217">VU#13217</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/1471" patch="1">HPSBUX9812-090</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7860">hp-rcmnds-gain-privileges(7860)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5550">oval:org.mitre.oval:def:5550</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.30"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1574" seq="1999-1574" published="1998-07-06" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/182777" patch="1">VU#182777</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX79909&amp;apar=only">IX79909</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7867">aix-nslookup-lex-bo(7867)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1575" seq="1999-1575" published="1999-09-10" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/23412">VU#23412</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/24839">VU#24839</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/26924">VU#26924</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/41408">VU#41408</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/9162">VU#9162</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-037">MS99-037</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7097">wang-kodak-activex-control(7097)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1576" seq="1999-1576" published="1999-09-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/25919">VU#25919</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719" adv="1">19990924 Several ActiveX Buffer Overruns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/666" patch="1">666</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3318">adobe-acrobat-pdf-bo(3318)</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1577" seq="1999-1577" published="1999-10-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/29795">VU#29795</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/669">669</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3314">ie-hhopen-bo(3314)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1578" seq="1999-1578" published="1999-09-24" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/37556" adv="1" patch="1">VU#37556</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/671" patch="1">671</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3311">ie-registration-wiz-bo(3311)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1579" seq="1999-1579" published="2000-12-14" modified="2018-08-13" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];242366">Q242366</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/3062">VU#3062</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6827">6827</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7107">winnt-xenroll-dos(7107)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1580" seq="1999-1580" published="1995-08-23" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html</ref>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=1853&amp;cid=1978" adv="1">AA-95.09</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-95.11.sun.sendmail-oR.vul" adv="1" patch="1">CA-1995-11</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/3278" adv="1">VU#3278</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7829">7829</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="5.59"/>
        <vers num="5.61"/>
        <vers num="5.65"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
        <vers num="4.1.3u1"/>
        <vers num="4.1.4"/>
        <vers num="4.1.4jl"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1581" seq="1999-1581" published="1997-12-23" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that cannot be decoded.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/kb/q178381/">Q178381</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/4923">VU#4923</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8231">winnt-snmp-oid-memory-leak(8231)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1582" seq="1999-1582" published="1998-07-15" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/pixest-pub.shtml">19980715 PIX Firewall "established" Command</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/6733">VU#6733</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8052">cisco-pix-established-bypass(8052)</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1583" seq="1999-1583" published="1999-09-30" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/872443" patch="1">VU#872443</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY02120&amp;apar=only" patch="1">IY02120</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8031">aix-nslookup-hostname-bo(8031)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1584" seq="1999-1584" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1" adv="1" patch="1">00124</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1993-18.html" adv="1" patch="1">CA-93.18</ref>
    </refs>
    <vuln_soft>
      <prod name="openwindows" vendor="sun">
        <vers num="3.0"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1585" seq="1999-1585" published="1999-12-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1" adv="1" patch="1">00124</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1586" seq="1999-1586" published="1999-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1995-12.html" adv="1" patch="1">CA-95.12</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/g-02.shtml" adv="1" patch="1">G-02</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/498">sun-loadmodule(498)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1587" seq="1999-1587" published="1999-12-31" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1015833" patch="1">1015833</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102215-1" patch="1">102215</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/19662">19662</ref>
      <ref source="MISC" url="http://www.sunmanagers.org/archives/1996/1383.html">http://www.sunmanagers.org/archives/1996/1383.html</ref>
      <ref source="VUPEN" url="http://www.vupen.com/english/advisories/2006/1123">ADV-2006-1123</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/25460">solaris-ps-information-disclosure(25460)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1470">oval:org.mitre.oval:def:1470</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="9.0" edition=":sparc"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1588" seq="1999-1588" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server">http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server</ref>
      <ref source="MISC" url="http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c">http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2319">2319</ref>
      <ref source="MISC" url="http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c">http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1589" seq="1999-1589" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-1992-10.html" patch="1">CA-1992-10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/357" patch="1">357</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="2.2.1"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1590" seq="1999-1590" published="1999-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitrary GIF files via ".." sequences in the image parameter, a different vulnerability than CVE-1999-0021.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/1997/Oct/0058.html" adv="1">19971010 Security flaw in Count.cgi (wwwcount)</ref>
    </refs>
    <vuln_soft>
      <prod name="wwwcount" vendor="wwwcount">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1591" seq="1999-1591" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00276.html">19990118 IIS4.0 and Visual Interdev</ref>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00277.html">19990119 Re: IIS4.0 and Visual Interdev</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/190">190</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0" edition="sp4"/>
      </prod>
      <prod name="visual_interdev" vendor="microsoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1592" seq="1999-1592" published="1999-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact.  NOTE: this might overlap CVE-1999-0129.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00159-1">00159</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/243" patch="1">243</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-1999-1593" seq="1999-1593" published="2009-01-14" modified="2009-01-15" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server.  NOTE: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00371.html">19990302 NT Domain DoS and Security Exploit with SAMBA Server</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jan/0264.html">20010117 Invalid WINS entries</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jan/0269.html">20010117 Re: Invalid WINS entries</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jan/0271.html">20010118 Re: Invalid WINS entries</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jan/0274.html">20010117 Re: Invalid WINS entries</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jan/0276.html">20010117 Re: Invalid WINS entries</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jan/0289.html">20010118 Re: Invalid WINS entries</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jan/0298.html">20010119 Re: Invalid WINS entries</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2221">2221</ref>
      <ref source="MISC" url="https://www2.sans.org/reading_room/whitepapers/win2k/185.php">https://www2.sans.org/reading_room/whitepapers/win2k/185.php</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2000-0001" seq="2000-0001" published="1999-12-23" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/888">888</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver" vendor="realnetworks">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0002" seq="2000-0002" published="1999-12-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94598388530358&amp;w=2">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/889">889</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=36B0596E.8D111D66@teleline.es">20000128 ZBServer 1.50-r1x exploit (WinNT)</ref>
    </refs>
    <vuln_soft>
      <prod name="zbserver" vendor="zbsoft">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0003" seq="2000-0003" published="1999-12-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94908470928258&amp;w=2">20000127 New SCO patches...</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0004" seq="2000-0004" published="1999-12-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94606572912422&amp;w=2">19991223 Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
    </refs>
    <vuln_soft>
      <prod name="zbserver" vendor="zbsoft">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0005" seq="2000-0005" published="1999-01-02" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP-UX aserver program allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5635">oval:org.mitre.oval:def:5635</ref>
    </refs>
    <vuln_soft>
      <prod name="aserver" vendor="hp">
        <vers num=""/>
      </prod>
      <prod name="9000" vendor="hp">
        <vers num="7_800"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="7.00"/>
        <vers num="7.02"/>
        <vers num="7.04"/>
        <vers num="7.06"/>
        <vers num="7.08"/>
        <vers num="8.00"/>
        <vers num="8.01"/>
        <vers num="8.02"/>
        <vers num="8.04"/>
        <vers num="8.05"/>
        <vers num="8.06"/>
        <vers num="8.07"/>
        <vers num="8.08"/>
        <vers num="8.09"/>
        <vers num="9.00"/>
        <vers num="9.01"/>
        <vers num="9.03"/>
        <vers num="9.04"/>
        <vers num="9.05"/>
        <vers num="9.06"/>
        <vers num="9.07"/>
        <vers num="9.08"/>
        <vers num="9.09"/>
        <vers num="9.10"/>
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.08"/>
        <vers num="10.09"/>
        <vers num="10.10"/>
        <vers num="10.16"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="10.30"/>
        <vers num="10.34"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0006" seq="2000-0006" published="1999-12-25" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">strace allows local users to read arbitrary files via memory mapped file names.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/39831">19991225 strace can lie</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4554">linux-strace(4554)</ref>
    </refs>
    <vuln_soft>
      <prod name="strace" vendor="paul_kranenburg">
        <vers num=""/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.3.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0007" seq="2000-0007" published="1999-12-29" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1740">1740</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4491">pccillin-proxy-remote-dos(4491)</ref>
    </refs>
    <vuln_soft>
      <prod name="pc-cillin" vendor="trend_micro">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0008" seq="2000-0008" published="1999-12-26" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FTPPro allows local users to read sensitive information, which is stored in plain text.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ftppro" vendor="1st_choice_software">
        <vers num="7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0009" seq="2000-0009" published="1999-12-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/907">907</ref>
    </refs>
    <vuln_soft>
      <prod name="optivity_net_architect" vendor="nortel">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0010" seq="2000-0010" published="1999-12-26" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="webwho+" vendor="tony_greenwood">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0011" seq="2000-0011" published="1999-12-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/906">906</ref>
    </refs>
    <vuln_soft>
      <prod name="simpleserver_www" vendor="analogx">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0012" seq="2000-0012" published="1999-12-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/898">898</ref>
    </refs>
    <vuln_soft>
      <prod name="msql" vendor="hughes">
        <vers num="2.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0013" seq="2000-0013" published="1999-12-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/909">909</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0014" seq="2000-0014" published="1999-12-28" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denial of service in Savant web server via a null character in the requested URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/897">897</ref>
    </refs>
    <vuln_soft>
      <prod name="savant_webserver" vendor="michael_lamont">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0015" seq="2000-0015" published="1999-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CascadeView TFTP server allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/910">910</ref>
    </refs>
    <vuln_soft>
      <prod name="cascadeview_ux" vendor="ascend">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0016" seq="2000-0016" published="1999-10-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/730">730</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_anywhere_mail_server" vendor="true_north">
        <vers num="2.3"/>
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0017" seq="2000-0017" published="1999-12-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0018" seq="2000-0018" published="1999-12-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/885">885</ref>
    </refs>
    <vuln_soft>
      <prod name="wmmon" vendor="windowmaker">
        <vers num="1.0b2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0019" seq="2000-0019" published="1999-03-04" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IMail POP3 daemon uses weak encryption, which allows local users to read files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="2006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0020" seq="2000-0020" published="1999-12-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="dns_pro" vendor="man_and_mice">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0021" seq="2000-0021" published="1999-12-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_server" vendor="lotus">
        <vers num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0022" seq="2000-0022" published="1999-12-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_server" vendor="lotus">
        <vers num="4.6"/>
        <vers num="4.6.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0023" seq="2000-0023" published="1999-12-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_server" vendor="lotus">
        <vers num="4.6"/>
        <vers num="4.6.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0024" seq="2000-0024" published="1999-12-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246401">Q246401</ref>
      <ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-061">MS99-061</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
      <prod name="site_server_commerce" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0025" seq="2000-0025" published="1999-12-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238606">Q238606</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-058">MS99-058</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
      <prod name="site_server_commerce" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0026" seq="2000-0026" published="1999-12-21" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/876">876</ref>
    </refs>
    <vuln_soft>
      <prod name="wmmon" vendor="windowmaker">
        <vers num="1.0b2"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0027" seq="2000-0027" published="1999-12-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/5381.php">ibm-netstat-race-condition(5381)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39962">19991227 IBM NetStation/UnixWare local root exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/900">900</ref>
    </refs>
    <vuln_soft>
      <prod name="network_station_manager" vendor="ibm">
        <vers num="2.0r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0028" seq="2000-0028" published="1999-12-23" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="3.0.2"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="4.0" edition="a_mac_os"/>
        <vers num="4.0.1" edition="sp2"/>
        <vers num="4.1"/>
        <vers num="4.5"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0029" seq="2000-0029" published="1999-12-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/901">901</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0030" seq="2000-0030" published="1999-12-22" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0031" seq="2000-0031" published="2000-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0032" seq="2000-0032" published="1999-12-22" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0033" seq="2000-0033" published="1999-12-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/899">899</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0034" seq="2000-0034" published="1999-12-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0035" seq="2000-0035" published="1999-12-28" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">resend command in Majordomo allows local users to gain privileges via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/902">902</ref>
    </refs>
    <vuln_soft>
      <prod name="majordomo" vendor="great_circle_associates">
        <vers num="1.94.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0036" seq="2000-0036" published="1999-12-22" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249082">Q249082</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-060">MS99-060</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.5" edition=":macintosh"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="5.0" edition=":macos"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0037" seq="2000-0037" published="1999-12-28" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-005.html">RHSA-2000:005</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/903">903</ref>
    </refs>
    <vuln_soft>
      <prod name="majordomo" vendor="great_circle_associates">
        <vers num="1.94.4"/>
        <vers num="1.94.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0038" seq="2000-0038" published="1999-12-23" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">glFtpD includes a default glftpd user account with a default password and a UID of 0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="glftpd" vendor="glftpd">
        <vers num="1.17.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0039" seq="2000-0039" published="1999-12-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/896">896</ref>
    </refs>
    <vuln_soft>
      <prod name="search_intranet" vendor="altavista">
        <vers num="2.0b"/>
        <vers num="2.3a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0040" seq="2000-0040" published="1999-12-23" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="glftpd" vendor="glftpd">
        <vers num="1.17.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0041" seq="2000-0041" published="1999-12-28" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/890">890</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0042" seq="2000-0042" published="1999-12-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/895">895</ref>
    </refs>
    <vuln_soft>
      <prod name="mail_server" vendor="csm">
        <vers num="1999-07b"/>
        <vers num="1999-07f"/>
        <vers num="1999-07g"/>
        <vers num="1999-07h"/>
        <vers num="1999-07i"/>
        <vers num="1999-07m"/>
        <vers num="2000-01a"/>
        <vers num="2000.8.a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0043" seq="2000-0043" published="1999-12-30" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/905">905</ref>
    </refs>
    <vuln_soft>
      <prod name="webcam_http_server" vendor="camshot">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0044" seq="2000-0044" published="2000-01-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/919">919</ref>
    </refs>
    <vuln_soft>
      <prod name="warftpd" vendor="jgaa">
        <vers num="1.67b2" prev="1"/>
        <vers num="1.70b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0045" seq="2000-0045" published="2000-01-11" modified="2019-10-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/926">926</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.22.27"/>
        <vers num="3.22.29"/>
        <vers num="3.23.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0046" seq="2000-0046" published="2000-01-10" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/929">929</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="0.99b_1.1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0047" seq="2000-0047" published="1999-10-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="pager" vendor="yahoo">
        <vers num="733"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0048" seq="2000-0048" published="2000-01-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://linux.corel.com/support/clos_patch1.htm">http://linux.corel.com/support/clos_patch1.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/928">928</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="corel">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0049" seq="2000-0049" published="2000-01-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/925">925</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="nullsoft">
        <vers num="2.0"/>
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0050" seq="2000-0050" published="2000-01-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13976&amp;Method=Full" adv="1" patch="1">ASB00-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/915">915</ref>
    </refs>
    <vuln_soft>
      <prod name="spectra" vendor="allaire">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0051" seq="2000-0051" published="2000-01-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13977&amp;Method=Full" adv="1" patch="1">ASB00-02</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/916">916</ref>
    </refs>
    <vuln_soft>
      <prod name="spectra" vendor="allaire">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0052" seq="2000-0052" published="2000-01-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/pam_advisory">20000104 PamSlam</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-001.html">RHSA-2000:001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/913">913</ref>
      <ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=linux-pam-userhelper">linux-pam-userhelper</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":i386"/>
        <vers num="6.1" edition=":i386"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="3.5b2"/>
        <vers num="4.2"/>
        <vers num="4.4"/>
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0053" seq="2000-0053" published="2000-01-04" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246731">Q246731</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/912">912</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-001">MS00-001</ref>
    </refs>
    <vuln_soft>
      <prod name="commercial_internet_system" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0054" seq="2000-0054" published="1999-01-03" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/921">921</ref>
    </refs>
    <vuln_soft>
      <prod name="home_free" vendor="solution_scripts">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0055" seq="2000-0055" published="2000-01-06" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/918">918</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0056" seq="2000-0056" published="2000-01-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/914">914</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0.8"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0057" seq="2000-0057" published="2000-01-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13978&amp;Method=Full" adv="1" patch="1">ASB00-03</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/917">917</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0058" seq="2000-0058" published="2000-01-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/2000-01/0085.html">20000105 Handspring Visor Network HotSync Security Hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/920">920</ref>
    </refs>
    <vuln_soft>
      <prod name="visor_network_hotsync" vendor="handspring">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0059" seq="2000-0059" published="2000-01-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/911">911</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0060" seq="2000-0060" published="1999-12-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94633851427858&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94647711311057&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/3765.php">avirt-rover-pop3-dos(3765)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/894">894</ref>
    </refs>
    <vuln_soft>
      <prod name="rover" vendor="avirt">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0061" seq="2000-0061" published="2000-01-07" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/923">923</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
        <vers num="5.5" edition="preview"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0062" seq="2000-0062" published="2000-01-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/922">922</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000104222219.B41650@schvin.net">20000104 [petrilli@digicool.com: [Zope] SECURITY ALERT]</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="1.10.3"/>
        <vers num="2.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0063" seq="2000-0063" published="2000-01-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref>
    </refs>
    <vuln_soft>
      <prod name="contivity" vendor="nortel">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0064" seq="2000-0064" published="2000-01-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref>
    </refs>
    <vuln_soft>
      <prod name="contivity" vendor="nortel">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0065" seq="2000-0065" published="2000-01-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="inetserv" vendor="avtronics">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0066" seq="2000-0066" published="2000-01-13" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="website_professional" vendor="oreilly">
        <vers num="2.3.18"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0067" seq="2000-0067" published="2000-01-11" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="merchant_connection_kit" vendor="cybercash">
        <vers num="3.2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0068" seq="2000-0068" published="1999-12-14" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94704437920965&amp;w=2">20000104 [rootshell] Security Bulletin #27</ref>
    </refs>
    <vuln_soft>
      <prod name="inbusiness_email_station" vendor="intel">
        <vers num="1.04" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0069" seq="2000-0069" published="2000-01-01" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The recover program in Solstice Backup allows local users to restore sensitive files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="solstice_backup" vendor="sun">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0070" seq="2000-0070" published="2000-01-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka "Spoofed LPC Port Request."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247869">Q247869</ref>
      <ref source="BINDVIEW" url="http://www.bindview.com/security/advisory/adv_NtImpersonate.html" adv="1" patch="1">20000113 Local Promotion Vulnerability in Windows NT 4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/934">934</ref>
      <ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=nt-spoofed-lpc-port">nt-spoofed-lpc-port</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-003">MS00-003</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0071" seq="2000-0071" published="2000-01-11" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94770020309953&amp;w=2">20000111 IIS still revealing paths for web directories</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94780058006791&amp;w=2">20000113 SV: IIS still revealing paths for web directories</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0072" seq="2000-0072" published="2000-01-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94823061421676&amp;w=2">20000118 Warning: VCasel security hole.</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/3867.php">vcasel-filename-trusting(3867)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/937">937</ref>
    </refs>
    <vuln_soft>
      <prod name="visual_casel" vendor="computer_power_solutions">
        <vers num="3.0"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0073" seq="2000-0073" published="1999-11-17" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249973">Q249973</ref>
      <ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=win-malformed-rtf-control-word">win-malformed-rtf-control-word</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-005">MS00-005</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0074" seq="2000-0074" published="2000-01-11" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="plusmail" vendor="powerscripts">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0075" seq="2000-0075" published="2000-01-13" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/930">930</ref>
    </refs>
    <vuln_soft>
      <prod name="msgcore" vendor="nosque">
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0076" seq="2000-0076" published="1999-12-30" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94709988232618&amp;w=2">19991230 vibackup.sh</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1439">1439</ref>
    </refs>
    <vuln_soft>
      <prod name="nvi" vendor="berkeley">
        <vers num="1.7x"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0077" seq="2000-0077" published="2000-01-02" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5549">oval:org.mitre.oval:def:5549</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0078" seq="2000-0078" published="2000-01-02" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5728">oval:org.mitre.oval:def:5728</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0079" seq="2000-0079" published="2000-01-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/936">936</ref>
    </refs>
    <vuln_soft>
      <prod name="cern_httpd" vendor="w3c">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0080" seq="2000-0080" published="2000-01-10" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">AIX techlibss allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94757136413681&amp;w=2">20000110 2nd attempt: AIX techlibss follows links</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/931">931</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0081" seq="2000-0081" published="2000-01-10" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. j&amp;#x41;vascript.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hotmail" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0082" seq="2000-0082" published="2000-01-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://net4tv.com/voice/story.cfm?StoryID=1823" adv="1">http://net4tv.com/voice/story.cfm?StoryID=1823</ref>
      <ref source="MISC" url="http://www.wired.com/news/technology/0,1282,33420,00.html" adv="1">http://www.wired.com/news/technology/0,1282,33420,00.html</ref>
    </refs>
    <vuln_soft>
      <prod name="webtv" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0083" seq="2000-0083" published="2000-04-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2031">HPSBUX0001-109</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0084" seq="2000-0084" published="2000-01-06" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CuteFTP uses weak encryption to store password information in its tree.dat file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cuteftp" vendor="globalscape">
        <vers num="2.x" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0085" seq="2000-0085" published="2000-01-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="hotmail" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0086" seq="2000-0086" published="2000-01-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/935">935</ref>
    </refs>
    <vuln_soft>
      <prod name="timbuktu_pro" vendor="netopia">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0087" seq="2000-0087" published="2000-01-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94790377622943&amp;w=2">20000113 Misleading sense of security in Netscape</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/4385.php">netscape-mail-notify-plaintext(4385)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.7"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0088" seq="2000-0088" published="2000-01-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/946" adv="1">946</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-002">MS00-002</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="97" edition="::ja"/>
        <vers num="97" edition="::ko"/>
        <vers num="97" edition="::zh"/>
        <vers num="2000" edition="::ja"/>
        <vers num="2000" edition="::ko"/>
        <vers num="2000" edition="::zh"/>
      </prod>
      <prod name="office_converter_pack" vendor="microsoft">
        <vers num="2000.0"/>
      </prod>
      <prod name="powerpoint" vendor="microsoft">
        <vers num="97" edition="::ja"/>
        <vers num="97" edition="::ko"/>
        <vers num="97" edition="::zh"/>
        <vers num="2000" edition="::ja"/>
        <vers num="2000" edition="::ko"/>
        <vers num="2000" edition="::zh"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="97" edition="::ja"/>
        <vers num="97" edition="::ko"/>
        <vers num="97" edition="::zh"/>
        <vers num="98" edition="::ja"/>
        <vers num="98" edition="::ko"/>
        <vers num="98" edition="::zh"/>
        <vers num="2000" edition="::ja"/>
        <vers num="2000" edition="::ko"/>
        <vers num="2000" edition="::zh"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0089" seq="2000-0089" published="2000-02-04" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249108">Q249108</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/947">947</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-004">MS00-004</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0090" seq="2000-0090" published="2000-01-17" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/943">943</ref>
    </refs>
    <vuln_soft>
      <prod name="workstation" vendor="vmware">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0091" seq="2000-0091" published="2000-01-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.inter7.com/vpopmail/">http://www.inter7.com/vpopmail/</ref>
      <ref source="MISC" url="http://www.inter7.com/vpopmail/ChangeLog">http://www.inter7.com/vpopmail/ChangeLog</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/942">942</ref>
    </refs>
    <vuln_soft>
      <prod name="vpopmail" vendor="inter7">
        <vers num="vchkpw_3.4.1"/>
        <vers num="vchkpw_3.4.2"/>
        <vers num="vchkpw_3.4.3"/>
        <vers num="vchkpw_3.4.4"/>
        <vers num="vchkpw_3.4.5"/>
        <vers num="vchkpw_3.4.6"/>
        <vers num="vchkpw_3.4.7"/>
        <vers num="vchkpw_3.4.8"/>
        <vers num="vchkpw_3.4.9"/>
        <vers num="vchkpw_3.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0092" seq="2000-0092" published="2000-01-19" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:01.make.asc">FreeBSD-SA-00:01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/939">939</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.4"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1" edition=":x86"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0093" seq="2000-0093" published="2000-01-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0094" seq="2000-0094" published="2000-02-16" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-001.txt.asc">NetBSD-SA2000-001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/940">940</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3995">netbsd-procfs(3995)</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0095" seq="2000-0095" published="2000-01-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/944">944</ref>
      <ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2041">HPSBUX0001-110</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.30"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0096" seq="2000-0096" published="2000-01-26" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/948">948</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="3.0"/>
        <vers num="3.0beta1"/>
        <vers num="3.0beta2"/>
        <vers num="3.0beta3"/>
        <vers num="3.0beta4"/>
        <vers num="3.0beta5"/>
        <vers num="3.0beta6"/>
        <vers num="3.0beta7"/>
        <vers num="3.0beta8"/>
        <vers num="3.0beta9"/>
        <vers num="3.0beta10"/>
        <vers num="3.0beta11"/>
        <vers num="3.0beta12"/>
        <vers num="3.0beta13"/>
        <vers num="3.0beta14"/>
        <vers num="3.0beta15"/>
        <vers num="3.0beta16"/>
        <vers num="3.0beta17"/>
        <vers num="3.0beta18"/>
        <vers num="3.0beta19"/>
        <vers num="3.0beta20"/>
        <vers num="3.0beta21"/>
        <vers num="3.0beta22"/>
        <vers num="3.0beta23"/>
        <vers num="3.0beta24"/>
        <vers num="3.0beta25"/>
        <vers num="3.0beta26"/>
        <vers num="3.0beta27"/>
        <vers num="3.0beta28"/>
        <vers num="3.0beta29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0097" seq="2000-0097" published="2000-01-26" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/950">950</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-006">MS00-006</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0098" seq="2000-0098" published="2000-01-26" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-006">MS00-006</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0099" seq="2000-0099" published="2000-01-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94848865112897&amp;w=2">20000119 Unixware ppptalk</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0100" seq="2000-0100" published="1999-12-29" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0045.html">20000115 Security Vulnerability with SMS 2.0 Remote Control</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-012">MS00-012</ref>
    </refs>
    <vuln_soft>
      <prod name="systems_management_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0101" seq="2000-0101" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="orderpage" vendor="make-a-store">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0102" seq="2000-0102" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="salescart" vendor="salescart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0103" seq="2000-0103" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="smartcart" vendor="netsmart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0104" seq="2000-0104" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="shoptron" vendor="web_express">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0105" seq="2000-0105" published="2000-02-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/962">962</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0106" seq="2000-0106" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="easycart" vendor="easycart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0107" seq="2000-0107" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000201">20000201</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/958">958</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0108" seq="2000-0108" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="intellivend" vendor="intelligent_vending_systems">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0109" seq="2000-0109" published="2000-01-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="multicsp" vendor="comstock">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0110" seq="2000-0110" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="websitetool" vendor="baron_consulting_group">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0111" seq="2000-0111" published="2000-01-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/953">953</ref>
    </refs>
    <vuln_soft>
      <prod name="rightfax" vendor="avt">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0112" seq="2000-0112" published="2000-02-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94973075614088&amp;w=2">20000202 vulnerability in Linux Debian default boot configuration</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/960">960</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0" edition="r5"/>
        <vers num="2.1"/>
        <vers num="2.2" edition=":pre_potato"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0113" seq="2000-0113" published="2000-01-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94934808714972&amp;w=2">20000128 SyGate 3.11 Port 7323 / Remote Admin hole</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94952641025328&amp;w=2">20000202 SV: SyGate 3.11 Port 7323 / Remote Admin hole</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94973281714994&amp;w=2">20000203 UPDATE: Sygate 3.11 Port 7323 Telnet Hole</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/952">952</ref>
      <ref source="CONFIRM" url="http://www.sybergen.com/support/fix.htm">http://www.sybergen.com/support/fix.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="sygate" vendor="sybergen">
        <vers num="2.0"/>
        <vers num="3.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0114" seq="2000-0114" published="2000-02-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0115" seq="2000-0115" published="2000-01-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0116" seq="2000-0116" published="2000-01-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra &lt; in front of the SCRIPT tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/954">954</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0117" seq="2000-0117" published="2000-01-30" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/951">951</ref>
    </refs>
    <vuln_soft>
      <prod name="cobalt_raq" vendor="sun">
        <vers num="1.0"/>
      </prod>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0118" seq="2000-0118" published="1999-06-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94935300520617&amp;w=2">20000130 RedHat 6.1 /and others/ PAM</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="3.0.3"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":alpha"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="5.2" edition=":sparc"/>
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="" edition=":x86"/>
        <vers num="1.1.3" edition="u1"/>
        <vers num="1.1.4" edition=":jl"/>
        <vers num="2.4" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0119" seq="2000-0119" published="1999-12-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94936267131123&amp;w=2">20000130 Bypass Virus Checking</ref>
    </refs>
    <vuln_soft>
      <prod name="virusscan" vendor="mcafee">
        <vers num=""/>
      </prod>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0120" seq="2000-0120" published="2000-01-01" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/955">955</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4025">allaire-spectra-ras-access(4025)</ref>
    </refs>
    <vuln_soft>
      <prod name="spectra" vendor="allaire">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0121" seq="2000-0121" published="2000-02-01" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248399">Q248399</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/963">963</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-007">MS00-007</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0122" seq="2000-0122" published="2000-02-03" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/470458/100/0/threaded">20070603 CERN &amp;#304;mage Map Dispatcher</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/964">964</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/34719">frontpage-cern-information-disclosure(34719)</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0123" seq="2000-0123" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="filemaker" vendor="filemaker">
        <vers num="" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0124" seq="2000-0124" published="2000-02-03" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/965">965</ref>
    </refs>
    <vuln_soft>
      <prod name="superscout" vendor="surfcontrol">
        <vers num="2.6.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0125" seq="2000-0125" published="2000-02-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/967">967</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002031027120.15921-100000@eight.wiretrip.net">20000203 RFP2K01 - "How I hacked Packetstorm" (wwwthreads advisory)</ref>
    </refs>
    <vuln_soft>
      <prod name="wwwthreads" vendor="wired_community_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0126" seq="2000-0126" published="2000-01-26" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0127" seq="2000-0127" published="2000-02-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed">http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/969">969</ref>
    </refs>
    <vuln_soft>
      <prod name="webspeed" vendor="progress">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0128" seq="2000-0128" published="2000-02-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.glazed.org/finger/changelog.txt">http://www.glazed.org/finger/changelog.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="the_finger_server" vendor="daniel_beckham">
        <vers num="0.80_beta"/>
        <vers num="0.81_beta"/>
        <vers num="0.82_beta"/>
        <vers num="0.83_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0129" seq="2000-0129" published="2000-02-04" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0130" seq="2000-0130" published="2000-01-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SCO scohelp program allows remote attackers to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.02a">SB-00.02a</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94908470928258&amp;w=2">20000127 New SCO patches...</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0131" seq="2000-0131" published="2000-02-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94960703721503&amp;w=2">20000201 war-ftpd 1.6x DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/966">966</ref>
    </refs>
    <vuln_soft>
      <prod name="warftpd" vendor="jgaa">
        <vers num="1.66x4s"/>
        <vers num="1.67.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0132" seq="2000-0132" published="2000-01-31" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/957">957</ref>
    </refs>
    <vuln_soft>
      <prod name="virtual_machine" vendor="microsoft">
        <vers num="2000"/>
        <vers num="3000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0133" seq="2000-0133" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/961">961</ref>
    </refs>
    <vuln_soft>
      <prod name="tiny_ftpdaemon" vendor="h._nomura">
        <vers num="0.52" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0134" seq="2000-0134" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="check_it_out" vendor="adgrafix_corporation">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0135" seq="2000-0135" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="atretail" vendor="atretail">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0136" seq="2000-0136" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cart32" vendor="mcmurtrey_whitaker_and_associates">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0137" seq="2000-0137" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="cartit" vendor="cartit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0138" seq="2000-0138" published="2000-05-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">A system has a distributed denial of service (DDOS) attack master, agent, or zombie installed, such as (1) Trinoo, (2) Tribe Flood Network (TFN), (3) Tribe Flood Network 2000 (TFN2K), (4) stacheldraht, (5) mstream, or (6) shaft.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95715370208598&amp;w=2">20000429 Source code to mstream, a DDoS tool</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95722093124322&amp;w=2">20000501 Re: Source code to mstream, a DDoS tool</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise48.php3">20000502 "mstream" Distributed Denial of Service Tool</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2000-0139" seq="2000-0139" published="1999-12-03" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/982">982</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_anywhere_mail_server" vendor="true_north">
        <vers num="3.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0140" seq="2000-0140" published="2000-02-10" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/980">980</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_anywhere_mail_server" vendor="true_north">
        <vers num="3.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0141" seq="2000-0141" published="2000-02-11" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/991">991</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=20000211224935.A13236@infomag.ape.relarn.ru">20000211 perl-cgi hole in UltimateBB by Infopop Corp.</ref>
      <ref source="MISC" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref>
    </refs>
    <vuln_soft>
      <prod name="ultimate_bulletin_board" vendor="infopop">
        <vers num="5.43"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0142" seq="2000-0142" published="2000-02-11" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="timbuktu_pro" vendor="netopia">
        <vers num="2.0"/>
        <vers num="5.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0143" seq="2000-0143" published="2000-02-11" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2"/>
        <vers num="1.2.1" prev="1"/>
      </prod>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.13"/>
        <vers num="1.2.14"/>
        <vers num="1.2.15"/>
        <vers num="1.2.16"/>
        <vers num="1.2.17"/>
        <vers num="1.2.18"/>
        <vers num="1.2.19"/>
        <vers num="1.2.20"/>
        <vers num="1.2.21"/>
        <vers num="1.2.22"/>
        <vers num="1.2.23"/>
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0144" seq="2000-0144" published="2000-02-07" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0034.html">20000207 Infosec.20000207.axis700.a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/971">971</ref>
    </refs>
    <vuln_soft>
      <prod name="700_network_document_server" vendor="axis">
        <vers num="1.0"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0145" seq="2000-0145" published="2000-02-05" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0146" seq="2000-0146" published="2000-02-07" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0049.html">20000207 Novell GroupWise 5.5 Enhancement Pack Web Access Denial of Servic e</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/972" adv="1" patch="1">972</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="5.5" edition=":enhancement_pack"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0147" seq="2000-0147" published="2000-02-08" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.04a" adv="1" patch="1">SB-00.04a</ref>
      <ref source="NAI" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0045.html" adv="1" patch="1">20000207 SNMPD default writable community string</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/973">973</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0148" seq="2000-0148" published="2000-02-08" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0053.html">20000208 Remote access vulnerability in all MySQL server versions</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/975">975</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.22.26"/>
        <vers num="3.22.27"/>
        <vers num="3.22.29"/>
        <vers num="3.22.30"/>
        <vers num="3.23.8"/>
        <vers num="3.23.9"/>
        <vers num="3.23.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0149" seq="2000-0149" published="2000-02-08" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0057.html">20000208 Zeus Web Server: Null Terminated Strings</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/977">977</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3982">zeus-server-null-string(3982)</ref>
    </refs>
    <vuln_soft>
      <prod name="zeus_web_server" vendor="zeus_technologies">
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0150" seq="2000-0150" published="2000-02-12" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/328867">VU#328867</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/979">979</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="4.1(6)"/>
        <vers num="4.1(6b)"/>
        <vers num="4.2(1)"/>
        <vers num="4.2(2)"/>
        <vers num="4.3"/>
        <vers num="4.4(4)"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0151" seq="2000-0151" published="2000-02-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/981" adv="1" patch="1">981</ref>
    </refs>
    <vuln_soft>
      <prod name="make" vendor="gnu">
        <vers num="3.77.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0152" seq="2000-0152" published="2000-03-30" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/976">976</ref>
    </refs>
    <vuln_soft>
      <prod name="bordermanager" vendor="novell">
        <vers num="3.0"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0153" seq="2000-0153" published="1999-03-26" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/989">989</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000801bf780a$9ad4b2e0$0100007f@localhost" adv="1">20000216 Doubledot bug in FrontPage FrontPage Personal Web Server.</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="personal_web_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0154" seq="2000-0154" published="2000-02-16" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.sco.com/security/">http://www.sco.com/security/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/988" adv="1" patch="1">988</ref>
      <ref source="NAI" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com">20000215 ARCserve symlink vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0155" seq="2000-0155" published="2000-02-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/993" adv="1" patch="1">993</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000701bf79cd$fdb5a620$4c4342a6@mightye.org">20000218 AUTORUN.INF Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0156" seq="2000-0156" published="2000-02-16" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-009">MS00-009</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3996">ie-image-source-redirect(3996)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0157" seq="2000-0157" published="2000-02-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-012.txt.asc">1999-012</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/992">992</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0158" seq="2000-0158" published="2000-02-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.06a" adv="1" patch="1">SB-00.06a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/997">997</ref>
      <ref source="NAI" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000001bf78af$6d0d47a0$4d2f45a1@jmagdych.na.nai.com" adv="1" patch="1">20000215 Remote Vulnerability in the MMDF SMTP Daemon</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=200002181449.JAA03436@dragonfly.corp.home.net">20000218 MMDF</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.2"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0159" seq="2000-0159" published="2000-02-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000217160216.13708.qmail@underground.org">HPSBUX0002-111</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0160" seq="2000-0160" published="2000-02-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000221103938.T21312@securityfocus.com">20000221 Microsoft signed software can be install software without prompting users</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.x"/>
        <vers num="5"/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0161" seq="2000-0161" published="2000-02-18" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/994">994</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-010">MS00-010</ref>
    </refs>
    <vuln_soft>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0162" seq="2000-0162" published="2000-02-18" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-011">MS00-011</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0" edition=":windows_98"/>
        <vers num="4.0" edition=":windows_nt"/>
        <vers num="4.1" edition=":windows_95"/>
        <vers num="4.1" edition=":windows_nt_4.0"/>
        <vers num="5" edition=":windows_nt_4.0"/>
        <vers num="5.0" edition=":windows_95"/>
        <vers num="5.0" edition=":windows_98"/>
      </prod>
      <prod name="visual_studio" vendor="microsoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0163" seq="2000-0163" published="2000-02-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/996">996</ref>
      <ref source="FREEBSD" url="http://www.securityfocus.com/templates/advisory.html?id=2092">FreeBSD-SA-00:03</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0164" seq="2000-0164" published="2000-02-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1004" adv="1">1004</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl">20000220 Sun Internet Mail Server</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris_isp_server" vendor="sun">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0165" seq="2000-0165" published="1999-11-13" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-023.shtml">K-023</ref>
      <ref source="FREEBSD" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.BSF.4.21.0002192249290.10784-100000@freefall.freebsd.org">FreeBSD-SA-00:04</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4195">delegate-proxy-bo(4105)</ref>
    </refs>
    <vuln_soft>
      <prod name="delegate" vendor="etl">
        <vers num="5.9"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0166" seq="2000-0166" published="2000-02-21" modified="2016-11-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95142756403323&amp;w=2">20000223 Pragma Systems response to USSRLabs report</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/995">995</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPGEJHCCAA.labs@ussrback.com">20000221 Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT</ref>
    </refs>
    <vuln_soft>
      <prod name="interaccess_telnetd_server" vendor="interaccess">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0167" seq="2000-0167" published="2000-02-15" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0002&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=8800">20000215 Crashing Inetinfo.exe by using a longfilename in the \mailroot\pickup directory</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0168" seq="2000-0168" published="2000-03-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1043">1043</ref>
      <ref source="MS" url="http://www.securityfocus.com/templates/advisory.html?id=2126">MS00-017</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCENECCAA.labs@ussrback.com">20000306 con\con is a old thing (anyway is cool)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0169" seq="2000-0169" published="2000-03-15" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&amp;'.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0211.html">20000314 Oracle Web Listener 4.0.x</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1053">1053</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0170" seq="2000-0170" published="2000-02-26" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1011">1011</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.2"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="3.5b2"/>
        <vers num="4.2"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0171" seq="2000-0171" published="2000-03-11" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0102.html">20000311 TESO advisory -- atsadc</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1048">1048</ref>
    </refs>
    <vuln_soft>
      <prod name="atsar_linux" vendor="at_computing">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0172" seq="2000-0172" published="2000-03-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1038">1038</ref>
    </refs>
    <vuln_soft>
      <prod name="mtr" vendor="matt_kimball_and_roger_wolff">
        <vers num="0.28"/>
        <vers num="0.41"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="3.5b2"/>
        <vers num="4.2"/>
        <vers num="4.4"/>
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0173" seq="2000-0173" published="2000-03-10" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.08a" adv="1" patch="1">SB-00.08a</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0174" seq="2000-0174" published="2000-03-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1040">1040</ref>
    </refs>
    <vuln_soft>
      <prod name="staroffice" vendor="sun">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0175" seq="2000-0175" published="2000-03-09" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1039">1039</ref>
    </refs>
    <vuln_soft>
      <prod name="staroffice" vendor="sun">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0176" seq="2000-0176" published="2000-02-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0417.html">20000228 Serv-U FTP-Server v2.4a showing real path</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1016" adv="1" patch="1">1016</ref>
    </refs>
    <vuln_soft>
      <prod name="serv-u" vendor="cat_soft">
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5a"/>
        <vers num="2.5b"/>
        <vers num="2.5c"/>
        <vers num="2.5d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0177" seq="2000-0177" published="2000-03-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0000.html">20000302 DNSTools v1.08 has no input validation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1028">1028</ref>
    </refs>
    <vuln_soft>
      <prod name="dnstools" vendor="dnstools_software">
        <vers num="1.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0178" seq="2000-0178" published="2000-02-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.foundrynet.com/bugTraq.html" adv="1">http://www.foundrynet.com/bugTraq.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1017">1017</ref>
    </refs>
    <vuln_soft>
      <prod name="serveriron" vendor="foundrynet">
        <vers num="5.1.10t12"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0179" seq="2000-0179" published="2000-02-28" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0387.html">20000228 HP Omniback remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1015" adv="1" patch="1">1015</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0006-115">HPSBUX0006-115</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_omniback_ii" vendor="hp">
        <vers num="2.55"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0180" seq="2000-0180" published="2000-03-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0201.html" adv="1">20000313 SOJOURN Search engine exposes files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1052" adv="1" patch="1">1052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4197">sojourn-file-read(4197)</ref>
    </refs>
    <vuln_soft>
      <prod name="sojourn" vendor="generation_terrorists_designs_and_concepts">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0181" seq="2000-0181" published="2000-03-11" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0119.html">20000311 Our old friend Firewall-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1054">1054</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0182" seq="2000-0182" published="2000-02-23" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="iplanet">
        <vers num="4.1_enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0183" seq="2000-0183" published="2000-03-10" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0093.html">20000310 Fwd: ircii-4.4 buffer overflow</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-008.html">RHSA-2000:008</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1046">1046</ref>
    </refs>
    <vuln_soft>
      <prod name="ircii" vendor="michael_sandrof">
        <vers num="4.4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0184" seq="2000-0184" published="2000-03-09" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0082.html">20000309</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1037">1037</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0185" seq="2000-0185" published="2000-03-08" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0069.html">20000308 RealServer exposes internal IP addresses</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1049">1049</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver" vendor="realnetworks">
        <vers num="5.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="realserver_g2" vendor="realnetworks">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0186" seq="2000-0186" published="2000-02-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-100.html">RHSA-2000:100</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1020">1020</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.4"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.2" edition=":i386"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="4.2"/>
        <vers num="4.4"/>
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0187" seq="2000-0187" published="2000-02-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html">20000227 EZ Shopper 3.0 shopping cart CGI remote command execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1014" adv="1" patch="1">1014</ref>
    </refs>
    <vuln_soft>
      <prod name="ezshopper" vendor="alex_heiphetz_group">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0188" seq="2000-0188" published="2000-02-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html">20000227 EZ Shopper 3.0 shopping cart CGI remote command execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1014" adv="1" patch="1">1014</ref>
    </refs>
    <vuln_soft>
      <prod name="ezshopper" vendor="alex_heiphetz_group">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0189" seq="2000-0189" published="2000-03-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1021">1021</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0190" seq="2000-0190" published="2000-03-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0016.html">20000303 Aol Instant Messenger DoS vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="3.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0191" seq="2000-0191" published="2000-02-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1025" adv="1" patch="1">1025</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=41256894.00492503.00@mailgw.backupcentralen.se" adv="1" patch="1">20000229 Infosec.20000229.axisstorpointcd.a</ref>
    </refs>
    <vuln_soft>
      <prod name="storpoint_cd" vendor="axis">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0192" seq="2000-0192" published="2000-03-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0029.html">20000304 OpenLinux 2.3: rpm_query</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1036">1036</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0193" seq="2000-0193" published="2000-03-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1030" adv="1" patch="1">1030</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003020436.PAA20168@jawa.chilli.net.au">20000302 Corel Linux 1.0 dosemu default configuration: Local root vuln</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="corel">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0194" seq="2000-0194" published="2000-02-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1007">1007</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="corel">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0195" seq="2000-0195" published="2000-02-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1008">1008</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="corel">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0196" seq="2000-0196" published="2000-02-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-006.html">RHSA-2000:006</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1018">1018</ref>
    </refs>
    <vuln_soft>
      <prod name="nmh" vendor="nmh">
        <vers num="1.0.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2" edition=":alpha"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="5.2" edition=":sparc"/>
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="3.5b2"/>
        <vers num="4.2"/>
        <vers num="4.4"/>
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0197" seq="2000-0197" published="2000-02-14" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0202.html">20000313 AT Jobs - Denial of serice/Privilege Elevation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1050" patch="1">1050</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0198" seq="2000-0198" published="2000-03-15" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0137.html">20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability</ref>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0206.html">20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1051">1051</ref>
    </refs>
    <vuln_soft>
      <prod name="mercur_imap4_server" vendor="atrium_software">
        <vers num="3.20.01"/>
      </prod>
      <prod name="mercur_mailserver" vendor="atrium_software">
        <vers num="3.2"/>
      </prod>
      <prod name="mercur_pop3_server" vendor="atrium_software">
        <vers num="3.20.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0199" seq="2000-0199" published="2000-03-14" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1055" adv="1" patch="1">1055</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0200" seq="2000-0200" published="2000-03-06" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1034">1034</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-015">MS00-015</ref>
    </refs>
    <vuln_soft>
      <prod name="clip_art" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
      <prod name="greetings" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="home_publishing" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0201" seq="2000-0201" published="2000-03-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1033">1033</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0202" seq="2000-0202" published="2000-03-08" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1041">1041</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-014">MS00-014</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0203" seq="2000-0203" published="2000-02-28" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.antivirus.com/download/ofce_patch_35.htm" adv="1" patch="1">http://www.antivirus.com/download/ofce_patch_35.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1013">1013</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=412FC0AFD62ED31191B40008C7E9A11A0D481D@srvnt04.previnet.it" adv="1">20000228 Re: TrendMicro OfficeScan tmlisten.exe DoS</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com">20000315 Trend Micro release patch for "OfficeScan DoS &amp; Message Replay" V ulnerabilies</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trend_micro">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0204" seq="2000-0204" published="2000-02-28" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0340.html">20000226 DOS in Trendmicro OfficeScan</ref>
      <ref source="MISC" url="http://www.antivirus.com/download/ofce_patch_35.htm">http://www.antivirus.com/download/ofce_patch_35.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1013">1013</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com">20000315 Trend Micro release patch for "OfficeScan DoS &amp; Message Replay" V ulnerabilies</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trend_micro">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0205" seq="2000-0205" published="2000-03-03" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0015.html" adv="1">20000303 TrendMicro OfficeScan, numerous security holes, remote files modification.</ref>
      <ref source="MISC" url="http://www.antivirus.com/download/ofce_patch_35.htm" adv="1" patch="1">http://www.antivirus.com/download/ofce_patch_35.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1013">1013</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com">20000315 Trend Micro release patch for "OfficeScan DoS &amp; Message Replay" V ulnerabilies</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trend_micro">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0206" seq="2000-0206" published="2000-03-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0023.html">20000305 Oracle installer problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1035">1035</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0207" seq="2000-0207" published="2000-03-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20000501-01-P">20000501-01-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1031">1031</ref>
    </refs>
    <vuln_soft>
      <prod name="infosearch" vendor="sgi">
        <vers num="1.0"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0208" seq="2000-0208" published="2000-02-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1026">1026</ref>
    </refs>
    <vuln_soft>
      <prod name="htdig" vendor="htdig">
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.2.0b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0209" seq="2000-0209" published="2000-02-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1012">1012</ref>
    </refs>
    <vuln_soft>
      <prod name="lynx" vendor="university_of_kansas">
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.8.3_dev22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0210" seq="2000-0210" published="2000-02-21" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/998">998</ref>
    </refs>
    <vuln_soft>
      <prod name="workshop" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0211" seq="2000-0211" published="2000-02-23" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1000">1000</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-013">MS00-013</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_services" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0212" seq="2000-0212" published="2000-02-24" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1001">1001</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4033">interaccess-telnet-dos(4033)</ref>
    </refs>
    <vuln_soft>
      <prod name="interaccess_telnetd_server" vendor="pragma_systems">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0213" seq="2000-0213" published="2000-02-23" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.sambar.com/session/highlight?url=/syshelp/history.htm&amp;words=security+&amp;color=red" adv="1">http://www.sambar.com/session/highlight?url=/syshelp/history.htm&amp;words=security+&amp;color=red</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1002" adv="1" patch="1">1002</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38B3E60A.6A84FEC3@cybcom.net" adv="1">20000223 Sambar Server alert!</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="4.2" prev="1" edition="beta7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0214" seq="2000-0214" published="2000-02-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1003">1003</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002242035500.30645-100000@unreal.sekure.org" adv="1">20000224 How the password could be recover using FTP Explorer's  registry!</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_explorer" vendor="ftpx">
        <vers num="1.00.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0215" seq="2000-0215" published="2000-02-08" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1019">1019</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0216" seq="2000-0216" published="2000-02-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0176.html" adv="1">20000229 mailbombing DoS easily exploitable against mail systems using MS mail clients.</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_messaging" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0217" seq="2000-0217" published="2000-02-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1006">1006</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2"/>
      </prod>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="1.2.13"/>
        <vers num="1.2.14"/>
        <vers num="1.2.15"/>
        <vers num="1.2.16"/>
        <vers num="1.2.17"/>
        <vers num="1.2.18"/>
        <vers num="1.2.19"/>
        <vers num="1.2.20"/>
        <vers num="1.2.21"/>
        <vers num="1.2.22"/>
        <vers num="1.2.23"/>
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
      <prod name="ssh2" vendor="ssh">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0218" seq="2000-0218" published="2000-02-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-002.0.txt">CSSA-2000-002.0</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0219" seq="2000-0219" published="2000-02-23" modified="2015-11-04" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1005" adv="1" patch="1">1005</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200002230248.NAA19185@cairo.anu.edu.au" adv="1">20000223 redhat 6.0: single user boot security hole</ref>
      <ref source="CONFIRM" url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10053">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10053</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0220" seq="2000-0220" published="2000-02-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="zonealarm" vendor="zonelabs">
        <vers num="2.0.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0221" seq="2000-0221" published="2000-02-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1009">1009</ref>
    </refs>
    <vuln_soft>
      <prod name="nautica_marlin" vendor="nortel">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0222" seq="2000-0222" published="2000-02-15" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/990">990</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000215155750.M4500@safe.hsc.fr" adv="1">20000215 Windows 2000 installation process weakness</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0223" seq="2000-0223" published="2000-03-10" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0107.html">20000311 TESO advisory -- wmcdplay</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1047">1047</ref>
    </refs>
    <vuln_soft>
      <prod name="wmcdplay" vendor="sam_hawker">
        <vers num="1.0_beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0224" seq="2000-0224" published="2000-02-15" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NAI" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com">20000215 ARCserve symlink vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1"/>
        <vers num="7.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0225" seq="2000-0225" published="2000-03-07" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1032" adv="1">1032</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003601bf854b$6893a090$0100a8c0@FIREWALKER">20000303 Pocsag remote access to client can't be disabled.</ref>
    </refs>
    <vuln_soft>
      <prod name="poc32" vendor="deti_fliegl">
        <vers num="2.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0226" seq="2000-0226" published="2000-03-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the "Chunked Transfer Encoding Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1066">1066</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-018">MS00-018</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0227" seq="2000-0227" published="2000-03-23" modified="2017-12-19" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0254.html">20000323 Local Denial-of-Service attack against Linux</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95421263519558&amp;w=2">20000328 Re: Local Denial-of-Service attack against Linux</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1072">1072</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4186">linux-domain-socket-dos(4186)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.12"/>
        <vers num="2.2.14"/>
        <vers num="2.3.99" edition="pre2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0228" seq="2000-0228" published="2000-03-17" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1058">1058</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-016">MS00-016</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_rights_manager" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0229" seq="2000-0229" published="2000-03-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0242.html">20000322 gpm-root</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_45.html">20000405 Security hole in gpm &lt; 1.18.1</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-009.html">RHSA-2000:009</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-045.html">RHSA-2000:045</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1069">1069</ref>
    </refs>
    <vuln_soft>
      <prod name="gpm" vendor="alessandro_rubini">
        <vers num="1.18.1"/>
        <vers num="1.19"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2" edition=":pre_potato"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":i386"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.2" edition=":i386"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0230" seq="2000-0230" published="2000-03-13" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0168.html">20000316 TESO &amp; C-Skills development advisory -- imwheel</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-016.html">RHSA-2000:016</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1060">1060</ref>
    </refs>
    <vuln_soft>
      <prod name="halloween_linux" vendor="halloween">
        <vers num="4.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0231" seq="2000-0231" published="2000-03-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0162.html">20000316 "TESO &amp; C-Skills development advisory -- kreatecd" at:</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1061">1061</ref>
    </refs>
    <vuln_soft>
      <prod name="halloween_linux" vendor="halloween">
        <vers num="4.0"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0232" seq="2000-0232" published="2000-03-30" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0306.html">20000330 Remote DoS Attack in Windows 2000/NT 4.0 TCP/IP Print Request Server Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1082">1082</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-021">MS00-021</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0233" seq="2000-0233" published="2000-03-15" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/vendor/2000-q1/0035.html">20000327 Security hole in SuSE Linux IMAP Server</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux_imap_server" vendor="suse">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0234" seq="2000-0234" published="2000-03-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1083">1083</ref>
      <ref source="CONFIRM" url="http://www.securityfocus.com/templates/advisory.html?id=2150">http://www.securityfocus.com/templates/advisory.html?id=2150</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000330220757.28456.qmail@securityfocus.com">20000330 Cobalt apache configuration exposes .htaccess</ref>
    </refs>
    <vuln_soft>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0235" seq="2000-0235" published="2000-03-27" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:10-orville-write.asc">FreeBSD-SA-00:10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1070">1070</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0236" seq="2000-0236" published="2000-03-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1063">1063</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38D2173D.24E39DD0@relaygroup.com">20000317 [SAFER 000317.EXP.1.5] Netscape Enterprise Server and '?wp' tags</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.0"/>
        <vers num="3.5.1"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0237" seq="2000-0237" published="2000-03-11" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1075" adv="1" patch="1">1075</ref>
      <ref source="MISC" url="http://zsh.stupidphat.com/advisory.cgi?000311-1">http://zsh.stupidphat.com/advisory.cgi?000311-1</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.5"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0238" seq="2000-0238" published="2000-03-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1064" adv="1">1064</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=s8d1f3e3.036@kib.co.kodiak.ak.us">20000317 DoS with NAVIEG</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="1.0" edition=":internet_email_gateways"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0239" seq="2000-0239" published="2000-03-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95325335825295&amp;w=2">20000315 Local / Remote  DoS Attack in MERCUR WebView WebMail-Client 1.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1056">1056</ref>
      <ref source="BUGTRAQ" url="http://www.ussrback.com/labs36.html">20000315 Local / Remote  DoS Attack in MERCUR WebView WebMail-Client 1.0</ref>
    </refs>
    <vuln_soft>
      <prod name="mercur_imap4_server" vendor="atrium_software">
        <vers num="3.20.01"/>
      </prod>
      <prod name="mercur_mailserver" vendor="atrium_software">
        <vers num="3.2"/>
      </prod>
      <prod name="mercur_pop3_server" vendor="atrium_software">
        <vers num="3.20.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0240" seq="2000-0240" published="2000-03-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1067" adv="1" patch="1">1067</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net">20000321 vqserver /........../</ref>
      <ref source="CONFIRM" url="http://www.vqsoft.com/vq/server/faqs/dotdotbug.html">http://www.vqsoft.com/vq/server/faqs/dotdotbug.html</ref>
    </refs>
    <vuln_soft>
      <prod name="vqserver" vendor="vqsoft">
        <vers num="1.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0241" seq="2000-0241" published="2000-03-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1068" adv="1">1068</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net" adv="1">20000321 vqserver /........../</ref>
    </refs>
    <vuln_soft>
      <prod name="vqserver" vendor="vqsoft">
        <vers num="1.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0242" seq="2000-0242" published="2000-03-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1073" adv="1" patch="1">1073</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-03-22&amp;msg=20000325224146.6839.qmail@securityfocus.com">20000325 Windmail allow web user get any file</ref>
    </refs>
    <vuln_soft>
      <prod name="windmail" vendor="geocel">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0243" seq="2000-0243" published="2000-03-25" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1076" adv="1" patch="1">1076</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=web-5645555@post2.rnci.com">20000324 AnalogX SimpleServer 1.03 Remote Crash" at:</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4189">simpleserver-exception-dos(4189)</ref>
    </refs>
    <vuln_soft>
      <prod name="simpleserver_www" vendor="analogx">
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0244" seq="2000-0244" published="2000-03-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1077" adv="1" patch="1">1077</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSO.4.20.0003290949280.2640-100000@naughty.monkey.org">20000328 Citrix ICA Basic Encryption</ref>
    </refs>
    <vuln_soft>
      <prod name="metaframe" vendor="citrix">
        <vers num="1.0" edition=":unix"/>
        <vers num="1.8" prev="1" edition=":windows_2000"/>
        <vers num="1.8" prev="1" edition=":windows_nt_4.0_tse"/>
      </prod>
      <prod name="winframe" vendor="citrix">
        <vers num="3.5_1.8_for_windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0245" seq="2000-0245" published="2000-03-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://sgigate.sgi.com/security/20000303-01-PX">20000303-01-PX</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-030.shtml">K-030</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1079">1079</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003290852.aa27218@blaze.arl.mil" adv="1" patch="1">20000328 Objectserver vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4206">irix-objectserver-create-accounts(4206)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0246" seq="2000-0246" published="2000-03-30" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=249599">Q249599</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1081">1081</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-019">MS00-019</ref>
    </refs>
    <vuln_soft>
      <prod name="commercial_internet_system" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="2.5"/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
      <prod name="proxy_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
      <prod name="site_server" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
      <prod name="site_server_commerce" vendor="microsoft">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0247" seq="2000-0247" published="2000-03-22" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:13.generic-nqs.asc">FreeBSD-SA-00:13</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0236.html" adv="1" patch="1">20000322 Local root compromise in GNQS 3.50.6 and 3.50.7</ref>
      <ref source="MISC" url="http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt">http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1842" adv="1">1842</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4306">generic-nqs-local-root(4306)</ref>
    </refs>
    <vuln_soft>
      <prod name="gnqs" vendor="gnqs">
        <vers num="3.50.6"/>
        <vers num="3.50.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0248" seq="2000-0248" published="2000-04-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise46.php3" adv="1" patch="1">20000424 Backdoor Password in Red Hat Linux Virtual Server Package</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0249" seq="2000-0249" published="2000-04-26" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1152">1152</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise47.php3">20000426 Insecure file handling in IBM AIX frcactrl program</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0250" seq="2000-0250" published="2000-04-14" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0072.html" adv="1">20000414 qnx crypt comprimised</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1114">1114</ref>
    </refs>
    <vuln_soft>
      <prod name="qnx" vendor="qnx">
        <vers num="4.25a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0251" seq="2000-0251" published="2000-04-06" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0021.html">HPSBUX0004-112</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1090">1090</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.4"/>
      </prod>
      <prod name="vvos" vendor="hp">
        <vers num="3.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0252" seq="2000-0252" published="2000-04-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html" adv="1">20000411 Back Door in Commercial Shopping Cart</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1115" adv="1">1115</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4975">dansie-shell-metacharacters(4975)</ref>
    </refs>
    <vuln_soft>
      <prod name="dansie_shopping_cart" vendor="craig_dansie">
        <vers num="3.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0253" seq="2000-0253" published="2000-04-11" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1115" adv="1">1115</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4621">shopping-cart-form-tampering(4621)</ref>
    </refs>
    <vuln_soft>
      <prod name="dansie_shopping_cart" vendor="craig_dansie">
        <vers num="3.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0254" seq="2000-0254" published="2000-04-14" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1115" adv="1">1115</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4954">dansie-form-variables(4954)</ref>
    </refs>
    <vuln_soft>
      <prod name="dansie_shopping_cart" vendor="craig_dansie">
        <vers num="3.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0255" seq="2000-0255" published="2000-04-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Nbase-Xyplex EdgeBlaster router allows remote attackers to cause a denial of service via a scan for the FormMail CGI program.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0022.html" adv="1">20000405 SilverBack Security Advisory: Nbase-Xyplex DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1091" adv="1">1091</ref>
    </refs>
    <vuln_soft>
      <prod name="edgeblaster" vendor="nbase-xyplex">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0256" seq="2000-0256" published="2000-04-19" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/470458/100/0/threaded">20070603 CERN &amp;#304;mage Map Dispatcher</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1117" adv="1" patch="1">1117</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-028">MS00-028</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/34720">frontpage-cern-bo(34720)</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="personal_web_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0257" seq="2000-0257" published="2000-04-19" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1118" adv="1" patch="1">1118</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0004171825340.10088-100000@nimue.tpi.pl" adv="1">20000418 Novell Netware 5.1 (server 5.00h, Dec 11, 1999)...</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0258" seq="2000-0258" published="2000-04-12" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1101" adv="1">1101</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-023">MS00-023</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0259" seq="2000-0259" published="2000-04-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1105" adv="1" patch="1">1105</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-024">MS00-024</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0260" seq="2000-0260" published="2000-04-14" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1109">1109</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-025">MS00-025</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="visual_interdev" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0261" seq="2000-0261" published="2000-04-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM's Statement</ref>
    </refs>
    <vuln_soft>
      <prod name="ken" vendor="avm">
        <vers num="1.3.10"/>
        <vers num="1.4.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0262" seq="2000-0262" published="2000-04-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM's Statement</ref>
    </refs>
    <vuln_soft>
      <prod name="ken" vendor="avm">
        <vers num="1.3.10"/>
        <vers num="1.4.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0263" seq="2000-0263" published="2000-04-16" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html" adv="1">20000416 xfs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1111" adv="1">1111</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0264" seq="2000-0264" published="2000-04-17" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1119">1119</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es">20000417 bugs in Panda Security 3.0</ref>
    </refs>
    <vuln_soft>
      <prod name="panda_security" vendor="panda">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0265" seq="2000-0265" published="2000-04-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1119" adv="1" patch="1">1119</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es" adv="1" patch="1">20000417 bugs in Panda Security 3.0</ref>
    </refs>
    <vuln_soft>
      <prod name="panda_security" vendor="panda">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0266" seq="2000-0266" published="2000-04-18" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1121">1121</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FC6130.D6D178FD@nat.bg">20000418 IE 5 security vulnerablity - circumventing Cross-frame security policy using Java/JavaScript (and disabling Active Scripting is not that easy)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0267" seq="2000-0267" published="2000-04-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/catos-enable-bypass-pub.shtml" adv="1">20000419 Cisco Catalyst Enable Password Bypass Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1122">1122</ref>
    </refs>
    <vuln_soft>
      <prod name="catos" vendor="cisco">
        <vers num="5.4(1)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0268" seq="2000-0268" published="2000-04-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml" adv="1" patch="1">20000420 Cisco IOS Software TELNET Option Handling Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1123">1123</ref>
    </refs>
    <vuln_soft>
      <prod name="accesspath" vendor="cisco">
        <vers num="ls-3"/>
        <vers num="ts-3"/>
        <vers num="vs-3"/>
      </prod>
      <prod name="as5200" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="as5300" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="as5800" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="system_controller_3640" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="3660_router" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="7100_router" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="7200_router" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="7500_router" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ubr7200" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="voice_gateway_as5800" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="11.3aa"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0(2)xf"/>
        <vers num="12.0(2)xg"/>
        <vers num="12.0(3)t2"/>
        <vers num="12.0(4)"/>
        <vers num="12.0(4)s"/>
        <vers num="12.0(4)t"/>
        <vers num="12.0(5)"/>
        <vers num="12.0(6)"/>
        <vers num="12.0(7)t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0269" seq="2000-0269" published="2000-04-18" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1125" adv="1" patch="1">1125</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref>
    </refs>
    <vuln_soft>
      <prod name="emacs" vendor="gnu">
        <vers num="20.0"/>
        <vers num="20.1"/>
        <vers num="20.2"/>
        <vers num="20.3"/>
        <vers num="20.4"/>
        <vers num="20.5"/>
        <vers num="20.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0270" seq="2000-0270" published="2000-04-18" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1126" adv="1" patch="1">1125</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref>
    </refs>
    <vuln_soft>
      <prod name="emacs" vendor="gnu">
        <vers num="20.0"/>
        <vers num="20.1"/>
        <vers num="20.2"/>
        <vers num="20.3"/>
        <vers num="20.4"/>
        <vers num="20.5"/>
        <vers num="20.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0271" seq="2000-0271" published="2000-04-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1125" adv="1" patch="1">1125</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref>
    </refs>
    <vuln_soft>
      <prod name="emacs" vendor="gnu">
        <vers num="20.0"/>
        <vers num="20.1"/>
        <vers num="20.2"/>
        <vers num="20.3"/>
        <vers num="20.4"/>
        <vers num="20.5"/>
        <vers num="20.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0272" seq="2000-0272" published="2000-04-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95625288231045&amp;w=2">20000420 Remote DoS attack in Real Networks Real Server Vulnerability</ref>
      <ref source="CONFIRM" url="http://service.real.com/help/faq/servg270.html">http://service.real.com/help/faq/servg270.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1128" adv="1" patch="1">1128</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver" vendor="realnetworks">
        <vers num="7.0"/>
        <vers num="basic"/>
        <vers num="g2_1.0"/>
        <vers num="intranet"/>
        <vers num="plus"/>
        <vers num="pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0273" seq="2000-0273" published="2000-04-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0031.html" adv="1">20000409 A funny way to DOS pcANYWHERE8.0 and 9.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1095" adv="1">1095</ref>
    </refs>
    <vuln_soft>
      <prod name="pcanywhere" vendor="symantec">
        <vers num="8.0"/>
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0274" seq="2000-0274" published="2000-04-10" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0035.html">20000410 linux trustees 1.5 long path name vulnerability</ref>
      <ref source="CONFIRM" url="http://www.braysystems.com/linux/trustees.html">http://www.braysystems.com/linux/trustees.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1096">1096</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_trustees" vendor="bray_systems">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0275" seq="2000-0275" published="2000-04-10" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0033.html">20000410 CRYPTOAdmin 4.1 server with PalmPilot PT-1 token 1.04 PIN Extract ion</ref>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/cc-pinextract.txt" adv="1">20000410 CRYPTOCard PalmToken PIN Extraction</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1097">1097</ref>
    </refs>
    <vuln_soft>
      <prod name="cryptoadmin" vendor="cryptocard">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0276" seq="2000-0276" published="2000-04-10" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1098" adv="1">1098</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000410131628.659.qmail@securityfocus.com">20000410 BeOS syscall bug</ref>
    </refs>
    <vuln_soft>
      <prod name="beos" vendor="be">
        <vers num="4.5"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0277" seq="2000-0277" published="2000-04-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OSVDB" url="http://www.osvdb.org/1272">1272</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1087" adv="1">1087</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-022">MS00-022</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="97"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0278" seq="2000-0278" published="2000-08-03" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0006.html">20000331 SalesLogix Eviewer Web App Bug: URL request crashes eviewer web application</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1089" adv="1">1089</ref>
    </refs>
    <vuln_soft>
      <prod name="corporation_eviewer" vendor="saleslogix">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0279" seq="2000-0279" published="2000-04-07" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0029.html">20000407 BeOS Networking DOS</ref>
      <ref source="MISC" url="http://bebugs.be.com/devbugs/detail.php3?oid=2505312">http://bebugs.be.com/devbugs/detail.php3?oid=2505312</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1100">1100</ref>
    </refs>
    <vuln_soft>
      <prod name="beos" vendor="be">
        <vers num="4.0"/>
        <vers num="4.5"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0280" seq="2000-0280" published="2000-04-03" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0018.html" adv="1">20000403 Win32 RealPlayer 6/7 Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1088" adv="1">1088</ref>
    </refs>
    <vuln_soft>
      <prod name="realplayer" vendor="realnetworks">
        <vers num="6.0" edition=":win"/>
        <vers num="7.0" edition=":win"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0281" seq="2000-0281" published="2000-03-26" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0277.html" adv="1">20000326 neat little napster bug</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0299.html" adv="1">20000330 Napster, Inc. response to Colten Edwards</ref>
    </refs>
    <vuln_soft>
      <prod name="napster_client" vendor="napster">
        <vers num="beta_5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0282" seq="2000-0282" published="2000-04-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html">ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0050.html" adv="1" patch="1">20000412 TalentSoft Web+ Input Validation Bug Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1102" adv="1" patch="1">1102</ref>
    </refs>
    <vuln_soft>
      <prod name="web+" vendor="talentsoft">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0283" seq="2000-0283" published="2000-04-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html" adv="1" patch="1">20000412 Performance Copilot for IRIX 6.5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1106" adv="1" patch="1">1106</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0284" seq="2000-0284" published="2000-04-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0074.html" adv="1">20000416 imapd4r1 v12.264</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0085.html">20000416 imapd4r1 v12.264</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1110" adv="1">1110</ref>
    </refs>
    <vuln_soft>
      <prod name="imap" vendor="university_of_washington">
        <vers num="12.264"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0285" seq="2000-0285" published="2000-04-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0076.html" adv="1">20000416 XFree86 server overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1306">1306</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.6"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0286" seq="2000-0286" published="2000-04-16" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">X fontserver xfs allows local users to cause a denial of service via malformed input to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html">20000416 xfs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1111" adv="1">1111</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0287" seq="2000-0287" published="2000-04-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0058.html">20000412 BizDB Search Script Enables Shell Command Execution at the Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1104" adv="1" patch="1">1104</ref>
    </refs>
    <vuln_soft>
      <prod name="technology_bizdb" vendor="cnc">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0288" seq="2000-0288" published="2000-04-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0049.html">20000412 Infonautic's getdoc.cgi may allow unauthorized access to documents</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2000-0289" seq="2000-0289" published="2000-03-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0284.html" adv="1">20000327 Security Problems with Linux 2.2.x IP Masquerading</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_48.html">20000520 Security hole in kernel &lt; 2.2.15</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1078" adv="1" patch="1">1078</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
        <vers num="2.2" edition=":pre_potato"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.10"/>
        <vers num="2.2.12"/>
        <vers num="2.2.14"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0290" seq="2000-0290" published="2000-03-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0005.html">20000331 Webstar 4.0 Buffer overflow vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1822">1822</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4792">macos-webstar-get-bo(4792)</ref>
    </refs>
    <vuln_soft>
      <prod name="webstar_http_server" vendor="4d">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0291" seq="2000-0291" published="2000-04-16" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0077.html" adv="1">20000416 StarOffice 5.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1112" adv="1">1112</ref>
    </refs>
    <vuln_soft>
      <prod name="staroffice" vendor="sun">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0292" seq="2000-0292" published="2000-04-19" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1129" adv="1">1129</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10004190908140.32750-100000@localhost.localdomain" adv="1">20000418 Adtran DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="mx2800" vendor="adtran">
        <vers num="m13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0293" seq="2000-0293" published="2000-05-02" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1130">1130</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1" edition="alpha"/>
        <vers num="6.2"/>
        <vers num="6.3" edition=":ppc"/>
        <vers num="6.3" edition="alpha"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0294" seq="2000-0294" published="2000-04-10" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1107">1107</ref>
      <ref source="FREEBSD" url="http://www.securityfocus.com/templates/advisory.html?id=2162">FreeBSD-SA-00:12</ref>
    </refs>
    <vuln_soft>
      <prod name="healthd" vendor="jim_housley">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0295" seq="2000-0295" published="2000-04-21" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="GENTOO" url="http://www.securityfocus.com/archive/1/305589/30/26390/threaded">GLSA-200301-07</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1131" adv="1" patch="1">1131</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000421010946.15318I-200000@schizo.strange.net" adv="1" patch="1">20000420 Remote vulnerability in LCDproc 0.4</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4315">lcdproc-remote-overflow(4315)</ref>
    </refs>
    <vuln_soft>
      <prod name="lcdproc" vendor="lcdproc">
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0296" seq="2000-0296" published="2000-03-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0011.html">20000331 fcheck v.2.7.45 and insecure use of Perl's system()</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1086" adv="1" patch="1">1086</ref>
    </refs>
    <vuln_soft>
      <prod name="fcheck" vendor="michael_a._gumienny">
        <vers num="2.7.45"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0297" seq="2000-0297" published="2000-04-03" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1085">1085</ref>
      <ref source="ALLAIRE" url="http://www2.allaire.com/handlers/index.cfm?ID=15099&amp;Method=Full">ASB00-06</ref>
    </refs>
    <vuln_soft>
      <prod name="forums" vendor="allaire">
        <vers num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0298" seq="2000-0298" published="2000-04-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0027.html">20000407 All Users startup folder left open if unattended install and OEMP reinstall=1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1758">1758</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4278">win2k-unattended-install(4278)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0299" seq="2000-0299" published="2000-04-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0020.html">20000404 WebObjects DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="webobjects" vendor="apple">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0300" seq="2000-0300" published="2000-04-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1093" adv="1" patch="1">1093</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000406030958.23902.qmail@securityfocus.com" adv="1">20000405 PcAnywhere weak password encryption</ref>
    </refs>
    <vuln_soft>
      <prod name="pcanywhere" vendor="symantec">
        <vers num="9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0301" seq="2000-0301" published="2000-04-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95505800117143&amp;w=2">20000405 Re: IMAIL (Ipswitch) DoS with Eudora (Qualcomm)</ref>
      <ref source="CONFIRM" url="http://support.ipswitch.com/kb/IM-20000208-DM02.htm" adv="1" patch="1">http://support.ipswitch.com/kb/IM-20000208-DM02.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1094" adv="1" patch="1">1094</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0302" seq="2000-0302" published="2000-03-31" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95453598317340&amp;w=2">20000331 Alert: MS Index Server (CISADV000330)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1084">1084</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-006">MS00-006</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0303" seq="2000-0303" published="2000-05-03" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.quake3arena.com/news/index.html" adv="1" patch="1">http://www.quake3arena.com/news/index.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1169">1169</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise50.php3">20000503 Vulnerability in Quake3Arena Auto-Download Feature</ref>
    </refs>
    <vuln_soft>
      <prod name="quake_3_arena" vendor="id_software">
        <vers num="1.16n"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0304" seq="2000-0304" published="2000-05-10" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1191">1191</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise52.php3">20000511 Microsoft IIS Remote Denial of Service Attack</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-031">MS00-031</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0305" seq="2000-0305" published="2000-05-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1236" adv="1">1236</ref>
      <ref source="BINDVIEW" url="http://www.securityfocus.com/templates/advisory.html?id=2240" adv="1">20000519 jolt2 - Remote DoS against NT, W2K, 9x</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-029">MS00-029</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="beos" vendor="be">
        <vers num="5.0"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0306" seq="2000-0306" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.02a" adv="1">SB-99.02</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-29&amp;msg=AAh6GYsGU1@leshka.chuvashia.su">19981229 Local/remote exploit for SCO UNIX.</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.04" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0307" seq="2000-0307" published="2001-03-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.07b" adv="1" patch="1">SB-99.07</ref>
    </refs>
    <vuln_soft>
      <prod name="open_desktop" vendor="sco">
        <vers num=""/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.05" prev="1"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0308" seq="2000-0308" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.08a" adv="1" patch="1">SB-99.08</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="2.0"/>
      </prod>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num="2.0"/>
        <vers num="2.01"/>
      </prod>
      <prod name="proxy_server" vendor="netscape">
        <vers num="2.5"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="2.1.3" prev="1"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0309" seq="2000-0309" published="2001-03-12" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#trctrap">19990212 i386 trace-trap handling when DDB was configured could cause a system crash.</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0310" seq="2000-0310" published="2001-03-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#maxqueue">19990217 IP fragment assembly can bog the machine excessively and cause problems.</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0311" seq="2000-0311" published="2000-04-20" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1145">1145</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-026">MS00-026</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0312" seq="2000-0312" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata25.html#cron" patch="1">19990830 In cron(8), make sure argv[] is NULL terminated in the fake popen() and run sendmail as the user, not as root.</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0313" seq="2000-0313" published="2001-03-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata.html#ifmedia">19991109 Any user can change interface media configurations.</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0314" seq="2000-0314" published="2001-03-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc" adv="1" patch="1">NetBSD-SA1999-004</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91893782027835&amp;w=2">19990213 traceroute as a flooder</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0.34"/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num="4.0"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3.3" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="2.0.34"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="2.0.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0315" seq="2000-0315" published="2001-03-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc" adv="1" patch="1">NetBSD-SA1999-004</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=91893782027835&amp;w=2">19990213 traceroute as a flooder</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0.34"/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num="4.0"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3.3" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="2.0.34"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="2.0.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0316" seq="2000-0316" published="2000-04-24" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0191.html">20000424 Solaris 7 x86 lp exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1143">1143</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0317" seq="2000-0317" published="2000-04-24" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0192.html" adv="1">20000424 Solaris 7 x86 lpset exploit.</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0236.html" adv="1">20000424 Solaris 7 x86 lpset exploit.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95729763119559&amp;w=2">20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1138" adv="1" patch="1">1138</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0318" seq="2000-0318" published="2000-04-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0057.html">20000413 Security problems with Atrium Mercur Mailserver 3.20</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1144" adv="1">1144</ref>
    </refs>
    <vuln_soft>
      <prod name="mercur_mailserver" vendor="atrium_software">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0319" seq="2000-0319" published="2000-04-23" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1146" adv="1" patch="1">1146</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=2694.000424@SECURITY.NNOV.RU">20000424 unsafe fgets() in sendmail's mail.local</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="eric_allman">
        <vers num="5.58"/>
        <vers num="5.59"/>
        <vers num="8.6.x"/>
        <vers num="8.7.1"/>
        <vers num="8.7.2"/>
        <vers num="8.7.3"/>
        <vers num="8.7.4"/>
        <vers num="8.7.5"/>
        <vers num="8.7.6"/>
        <vers num="8.7.x"/>
        <vers num="8.8"/>
        <vers num="8.8.1"/>
        <vers num="8.8.2"/>
        <vers num="8.8.3"/>
        <vers num="8.8.4"/>
        <vers num="8.8.5"/>
        <vers num="8.8.x"/>
        <vers num="8.9.1"/>
        <vers num="8.9.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0320" seq="2000-0320" published="2000-04-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1133" adv="1" patch="1">1133</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=9763.000421@SECURITY.NNOV.RU" adv="1" patch="1">20000421 unsafe fgets() in qpopper</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="2.53"/>
        <vers num="3.0"/>
      </prod>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0321" seq="2000-0321" published="2000-04-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0190.html" adv="1">20000424 Buffer Overflow in version .14</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1147" adv="1">1147</ref>
    </refs>
    <vuln_soft>
      <prod name="icradius" vendor="icradius">
        <vers num="0.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0322" seq="2000-0322" published="2000-04-24" modified="2016-09-16" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-014.html">RHSA-2000:014</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1149" adv="1" patch="1">1149</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Enip.BSO.23.0004241601140.28851-100000@www.whitehats.com">20000424 piranha default password/exploit</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0323" seq="2000-0323" published="1999-07-28" modified="2018-10-15" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-22&amp;msg=19990729195531.25108.qmail@underground.org">19990728 Alert : MS Office 97 Vulnerability</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-030">MS99-030</ref>
      <ref source="XF" url="https://web.archive.org/web/20000819203059/http://xforce.iss.net:80/alerts/vol-4_num-7.php#jet-text-isam">jet-text-isam</ref>
      <ref source="BID" url="https://www.securityfocus.com/bid/595">595</ref>
    </refs>
    <vuln_soft>
      <prod name="jet" vendor="microsoft">
        <vers num="3.5"/>
        <vers num="3.51"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0324" seq="2000-0324" published="2000-04-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0201.html">20010211 Symantec pcAnywhere 9.0 DoS / Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0258.html">20010212 Re: Symantec pcAnywhere 9.0 DoS / Buffer Overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/4347.php">pcanywhere-tcpsyn-dos(4347)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1150" adv="1">1150</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000425150157.13567A-100000@sword.damocles.com" adv="1">20000425 Denial of Service Against pcAnywhere.</ref>
    </refs>
    <vuln_soft>
      <prod name="pcanywhere" vendor="symantec">
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="9.0"/>
        <vers num="9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0325" seq="2000-0325" published="1999-08-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/548">548</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-030">MS99-030</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3155">jet-vba-shell(3155)</ref>
    </refs>
    <vuln_soft>
      <prod name="jet" vendor="microsoft">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0326" seq="2000-0326" published="2000-04-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.on.com/support/mmxp.nsf/31af51e08bcc93eb852565a90056138b/11af70407a16b165852568c50056a952?OpenDocument" adv="1">http://support.on.com/support/mmxp.nsf/31af51e08bcc93eb852565a90056138b/11af70407a16b165852568c50056a952?OpenDocument</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1151" adv="1">1151</ref>
    </refs>
    <vuln_soft>
      <prod name="meeting_maker" vendor="on_technology">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0327" seq="2000-0327" published="1999-10-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93993545118416&amp;w=2">19991014 Another Microsoft Java Flaw Disovered</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-045">MS99-045</ref>
    </refs>
    <vuln_soft>
      <prod name="virtual_machine" vendor="microsoft">
        <vers num="2000"/>
        <vers num="3000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0328" seq="2000-0328" published="1999-08-24" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/604">604</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.19990824165629.00abcb40@192.168.124.1">19990824 NT Predictable Initial TCP Sequence numbers - changes observed with SP4</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-046">MS99-046</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0329" seq="2000-0329" published="1999-11-11" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-048">MS99-048</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0" edition=":windows_98"/>
        <vers num="4.0" edition=":windows_nt"/>
        <vers num="4.0.1" edition=":windows_95"/>
        <vers num="4.0.1" edition=":windows_98"/>
        <vers num="4.0.1" edition=":windows_nt"/>
        <vers num="4.1" edition=":windows_95"/>
        <vers num="4.1" edition=":windows_98"/>
        <vers num="4.1" edition=":windows_nt_4.0"/>
        <vers num="5" edition=":windows_nt_4.0"/>
        <vers num="5.0" edition=":windows_2000"/>
        <vers num="5.0" edition=":windows_95"/>
        <vers num="5.0" edition=":windows_98"/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="4.27.3110.1"/>
        <vers num="4.72.2106.4"/>
        <vers num="4.72.3120.0"/>
        <vers num="4.72.3612.1700"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0330" seq="2000-0330" published="1999-11-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/1999/ms99-049">MS99-049</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0331" seq="2000-0331" published="2000-04-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0147.html">20000421 CMD.EXE overflow (CISADV000420)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1135" adv="1" patch="1">1135</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-027">MS00-027</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0332" seq="2000-0332" published="2000-05-03" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1164" adv="1">1164</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000503091316.99073.qmail@hotmail.com">20000502 Fun with UltraBoard V1.6X</ref>
    </refs>
    <vuln_soft>
      <prod name="ultraboard" vendor="ultrascripts">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0333" seq="2000-0333" published="1999-05-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1165" adv="1" patch="1">1165</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SOL.4.10.10005021942380.2077-100000@paranoia.pgci.ca" adv="1">20000502 Denial of service attack against tcpdump</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.8.4"/>
        <vers num="0.8.5"/>
        <vers num="0.8.6"/>
      </prod>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.4"/>
        <vers num="3.5a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0334" seq="2000-0334" published="2000-04-24" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=15411&amp;Method=Full" adv="1" patch="1">ASB00-10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1181">1181</ref>
    </refs>
    <vuln_soft>
      <prod name="spectra" vendor="allaire">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0335" seq="2000-0335" published="2000-05-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1166" adv="1">1166</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
      </prod>
      <prod name="bind" vendor="isc">
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0336" seq="2000-0336" published="2000-04-21" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-009.0.txt" adv="1" patch="1">CSSA-2000-009.0</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-012.html">RHSA-2000:012</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1232">1232</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-May/000009.html">TLSA2000010-1</ref>
    </refs>
    <vuln_soft>
      <prod name="openldap" vendor="openldap">
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.2.10"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="4.2"/>
        <vers num="4.4"/>
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0337" seq="2000-0337" published="2000-04-24" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0188.html">20000424 Solaris x86 Xsun overflow.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1140">1140</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0338" seq="2000-0338" published="2000-04-23" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1136" adv="1" patch="1">1136</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000423174038.A520%40clico.pl">20000423 CVS DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="cvs" vendor="cvs">
        <vers num="1.10.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0339" seq="2000-0339" published="2000-04-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1137">1137</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000421044123.2353.qmail@securityfocus.com">20000420 ZoneAlarm</ref>
    </refs>
    <vuln_soft>
      <prod name="zonealarm" vendor="zonelabs">
        <vers num="2.2.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0340" seq="2000-0340" published="2000-04-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1155" adv="1" patch="1">1155</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00042902575201.09597@wintermute-pub">20000428 SuSE 6.3 Gnomelib buffer overflow</ref>
      <ref source="CONFIRM" url="http://www.suse.com/us/support/download/updates/axp_63.html">http://www.suse.com/us/support/download/updates/axp_63.html</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0341" seq="2000-0341" published="2000-05-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=95736106504870&amp;w=2">20000501 Remote DoS attack in CASSANDRA NNTPServer v1.10 from ATRIUM</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1156" adv="1">1156</ref>
    </refs>
    <vuln_soft>
      <prod name="cassandra_nntp_server" vendor="atrium_software">
        <vers num="1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0342" seq="2000-0342" published="2000-04-28" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077" adv="1">http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077</ref>
      <ref source="MISC" url="http://www.peacefire.org/security/stealthattach/explanation.html">http://www.peacefire.org/security/stealthattach/explanation.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1157">1157</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0343" seq="2000-0343" published="2000-05-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1158" adv="1">1158</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005021736.TAA01991@ALuSSi">20000502 spj-003-000 - S0ftPj Advisory</ref>
    </refs>
    <vuln_soft>
      <prod name="sniffit" vendor="brecht_claerhout">
        <vers num="0.3.6hip"/>
        <vers num="0.3.7beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0344" seq="2000-0344" published="2000-05-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1160" adv="1">1160</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0005012042550.6419-100000@ferret.lmh.ox.ac.uk" adv="1" patch="1">20000501 Linux knfsd DoS issue</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.1"/>
        <vers num="2.2.0"/>
        <vers num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0345" seq="2000-0345" published="2000-05-03" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1161" adv="1" patch="1">1161</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000502222246.28423.qmail@securityfocus.com">20000502 Possible issue with Cisco on-line help?</ref>
    </refs>
    <vuln_soft>
      <prod name="router_2500" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="router_2600" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="router_3600" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="router_4000" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="router_7200" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="router_7500" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="9.14"/>
        <vers num="11.1"/>
        <vers num="11.1(13)"/>
        <vers num="11.1(13)aa"/>
        <vers num="11.1(13)ca"/>
        <vers num="11.1(13)ia"/>
        <vers num="11.1(15)ca"/>
        <vers num="11.1(16)"/>
        <vers num="11.1(16)aa"/>
        <vers num="11.1(16)ia"/>
        <vers num="11.1(17)cc"/>
        <vers num="11.1(17)ct"/>
        <vers num="11.2"/>
        <vers num="11.2(4)f1"/>
        <vers num="11.2(8)"/>
        <vers num="11.2(8)p"/>
        <vers num="11.2(8)sa1"/>
        <vers num="11.2(8)sa3"/>
        <vers num="11.2(8)sa5"/>
        <vers num="11.2(9)p"/>
        <vers num="11.2(9)xa"/>
        <vers num="11.2(10)"/>
        <vers num="11.2(10)bc"/>
        <vers num="11.2(17)"/>
        <vers num="11.2p"/>
        <vers num="12.0"/>
        <vers num="12.0(1)w"/>
        <vers num="12.0(1)xa3"/>
        <vers num="12.0(1)xb"/>
        <vers num="12.0(1)xe"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0(2)xf"/>
        <vers num="12.0(2)xg"/>
        <vers num="12.0(3)t2"/>
        <vers num="12.0(4)"/>
        <vers num="12.0(4)s"/>
        <vers num="12.0(4)t"/>
        <vers num="12.0(5)"/>
        <vers num="12.0(5)t1"/>
        <vers num="12.0(6)"/>
        <vers num="12.0(7)t"/>
        <vers num="12.0(8)"/>
        <vers num="12.0(9)s"/>
        <vers num="12.0db"/>
        <vers num="12.0s"/>
        <vers num="12.0t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0346" seq="2000-0346" published="2000-05-02" modified="2017-11-27" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://asu.info.apple.com/swupdates.nsf/artnum/n11670">http://asu.info.apple.com/swupdates.nsf/artnum/n11670</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1162" adv="1">1162</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000502133240.21807.qmail@securityfocus.com" adv="1">20000502 INFO:AppleShare IP 6.3.2 squashes security bug</ref>
    </refs>
    <vuln_soft>
      <prod name="appleshare" vendor="apple">
        <vers num="6.1" edition="::ja"/>
        <vers num="6.2" edition="::ja"/>
        <vers num="6.3" edition="::ja"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0347" seq="2000-0347" published="2000-05-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=95737580922397&amp;w=2">20000501 el8.org advisory - Win 95/98 DoS (RFParalyze.c)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1163">1163</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0348" seq="2000-0348" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A vulnerability in the Sendmail configuration file sendmail.cf as installed in SCO UnixWare 7.1.0 and earlier allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.10a" adv="1" patch="1">SB-99.10</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0349" seq="2000-0349" published="2001-03-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the passthru driver in SCO UnixWare 7.1.0 allows an attacker to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.13a" adv="1" patch="1">SB-99.13</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0350" seq="2000-0350" published="2000-05-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://advice.networkice.com/advice/Support/KB/q000166/">http://advice.networkice.com/advice/Support/KB/q000166/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1216">1216</ref>
      <ref source="MISC" url="http://www.securityfocus.com/templates/advisory.html?id=2220">http://www.securityfocus.com/templates/advisory.html?id=2220</ref>
    </refs>
    <vuln_soft>
      <prod name="icecap_manager" vendor="networkice">
        <vers num="2.0.23" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0351" seq="2000-0351" published="2001-03-12" modified="2011-03-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove software packages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.09b" adv="1" patch="1">SB-99.09</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0352" seq="2000-0352" published="1999-11-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-036.0.txt">CSSA-1999-036.0</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_36.html">19991227 Security hole in Pine &lt; 4.21</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/810">810</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9911171818220.12375-100000@ray.compu-aid.com">19991117 Pine: expanding env vars in URLs (seems to be fixed as of 4.21)</ref>
    </refs>
    <vuln_soft>
      <prod name="pine" vendor="university_of_washington">
        <vers num="4.20"/>
        <vers num="4.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0353" seq="2000-0353" published="1999-06-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/pine_update_announcement.html">19990911 Update for Pine (fixed IMAP support)</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_6.html">19990628 Execution of commands in Pine 4.x</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html" adv="1" patch="1">http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1247">1247</ref>
    </refs>
    <vuln_soft>
      <prod name="pine" vendor="university_of_washington">
        <vers num="3.98"/>
        <vers num="4.0"/>
        <vers num="4.2"/>
        <vers num="4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0354" seq="2000-0354" published="2000-09-28" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/1999/19991018">19991018 Incorrect directory name handling in mirror</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_22.html">19991001 Security hole in mirror</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/681">681</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=15769.990928@tomcat.ru">19990928 mirror 2.9 hole</ref>
    </refs>
    <vuln_soft>
      <prod name="mirror" vendor="lee_mcloughlin">
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0355" seq="2000-0355" published="1999-08-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_21.html">19990920 Security hole in pbpg</ref>
    </refs>
    <vuln_soft>
      <prod name="pbpg" vendor="bent_bagger">
        <vers num="1.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0356" seq="2000-0356" published="1999-10-13" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/697">697</ref>
      <ref source="REDHAT" url="http://www.securityfocus.com/templates/advisory.html?id=1789">RHSA-1999:040</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.1" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0357" seq="2000-0357" published="1999-12-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999058-01.html">RHSA-1999:058-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0358" seq="2000-0358" published="1999-12-03" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999058-01.html">RHSA-1999:058-01</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0359" seq="2000-0359" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1626.html">19991113 thttpd 2.04 stack overflow (VD#6)</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html">19991116 Security hole in thttpd 1.90a - 2.04</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1248">1248</ref>
    </refs>
    <vuln_soft>
      <prod name="thttpd" vendor="acme_labs">
        <vers num="1.90a"/>
        <vers num="1.95"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0360" seq="2000-0360" published="2000-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-038.0.txt" adv="1" patch="1">CSSA-1999-038.0</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_34.html">19991124 Security hole in inn &lt;= 2.2.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1249">1249</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="1.4sec"/>
        <vers num="1.4sec2"/>
        <vers num="1.4unoff3"/>
        <vers num="1.4unoff4"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.7"/>
        <vers num="1.7.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0361" seq="2000-0361" published="1999-12-14" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_35.html">19991214 Security hole in wvdial &lt;= 1.4</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0362" seq="2000-0362" published="1999-10-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html">19991019 Security hole in cdwtools &lt; 093</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/738">738</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0363" seq="2000-0363" published="1999-10-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html">19991019 Security hole in cdwtools &lt; 093</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/738">738</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0364" seq="2000-0364" published="1999-06-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92877527701347&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92886009012161&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
      <ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999014_01.html">RHSA1999014_01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/309">309</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0365" seq="2000-0365" published="1999-06-01" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92877527701347&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=92886009012161&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref>
      <ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999014_01.html">RHSA1999014_01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/308">308</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0366" seq="2000-0366" published="1999-12-02" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/1999/19991202">19991202 problem restoring symlinks</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1442">1442</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0367" seq="2000-0367" published="1999-02-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/1999/19990218" adv="1">19990218 Root exploit in eterm</ref>
    </refs>
    <vuln_soft>
      <prod name="eterm" vendor="michael_jennings">
        <vers num="0.8.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0368" seq="2000-0368" published="2001-03-12" modified="2016-09-21" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-009.shtml" adv="1" patch="1">J-009</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/770/ioshist-pub.shtml" adv="1" patch="1">19981014 Cisco IOS Command History Release at Login Prompt</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0369" seq="2000-0369" published="1999-10-08" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-029.1.txt">CSSA-1999-029.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1266">1266</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0370" seq="2000-0370" published="1999-01-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-001.0.txt" adv="1" patch="1">CSSA-1999-001.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1268">1268</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0371" seq="2000-0371" published="1999-03-01" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-005.0.txt" adv="1" patch="1">CSSA-1999-005.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1269">1269</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0372" seq="2000-0372" published="2000-07-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-014.0.txt" adv="1" patch="1">CSSA-1999-014.0</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2268">linux-rmt(2268)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0373" seq="2000-0373" published="1999-06-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-015.0.txt">CSSA-1999-015.0</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA1999015_01.html" adv="1" patch="1">RHSA-1999:015-01</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/2266">kde-kvt(2266)</ref>
    </refs>
    <vuln_soft>
      <prod name="kvt" vendor="kde">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0374" seq="2000-0374" published="1999-08-22" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-021.0.txt">CSSA-1999-021.0</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:025">MDKSA-2002:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1446">1446</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4856">xdmcp-kdm-default-configuration(4856)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0375" seq="2000-0375" published="2001-03-12" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0376" seq="2000-0376" published="2000-06-07" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1324">1324</ref>
    </refs>
    <vuln_soft>
      <prod name="filo" vendor="i-drive">
        <vers num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0377" seq="2000-0377" published="2000-06-08" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=264684">Q264684</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1331">1331</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-040">MS00-040</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1021">oval:org.mitre.oval:def:1021</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0378" seq="2000-0378" published="2000-05-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0023.html">20000502 pam_console bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1176">1176</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0379" seq="2000-0379" published="2000-05-16" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.netopia.com/equipment/purchase/fmw_update.html">http://www.netopia.com/equipment/purchase/fmw_update.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1177">1177</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005082054.NAA32590@linux.mtndew.com" adv="1" patch="1">20000507 Advisory: Netopia R9100 router vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="r-series_routers" vendor="netopia">
        <vers num="4.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0380" seq="2000-0380" published="2000-04-26" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0261.html">20000426 Cisco HTTP possible bug:</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml">20000514 Cisco IOS HTTP Server Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1154">1154</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.1"/>
        <vers num="11.2"/>
        <vers num="11.2(4)f1"/>
        <vers num="11.2(8)"/>
        <vers num="11.2(8)p"/>
        <vers num="11.2(9)p"/>
        <vers num="11.2(9)xa"/>
        <vers num="11.2(10)"/>
        <vers num="11.2(10)bc"/>
        <vers num="11.2(17)"/>
        <vers num="11.2p"/>
        <vers num="11.3"/>
        <vers num="11.3(1)"/>
        <vers num="11.3(1)ed"/>
        <vers num="11.3(1)t"/>
        <vers num="11.3t"/>
        <vers num="12.0"/>
        <vers num="12.0(1)w"/>
        <vers num="12.0(1)xa3"/>
        <vers num="12.0(1)xb"/>
        <vers num="12.0(1)xe"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0(2)xf"/>
        <vers num="12.0(2)xg"/>
        <vers num="12.0(3)t2"/>
        <vers num="12.0(4)"/>
        <vers num="12.0(4)s"/>
        <vers num="12.0(4)t"/>
        <vers num="12.0(5)"/>
        <vers num="12.0(5)t1"/>
        <vers num="12.0(6)"/>
        <vers num="12.0(7)t"/>
        <vers num="12.0(8)"/>
        <vers num="12.0(9)s"/>
        <vers num="12.0db"/>
        <vers num="12.0s"/>
        <vers num="12.0t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0381" seq="2000-0381" published="2000-05-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0067.html">20000505 Black Watch Labs Vulnerability Alert</ref>
      <ref source="MISC" url="http://www.perfectotech.com/blackwatchlabs/vul5_05.html">http://www.perfectotech.com/blackwatchlabs/vul5_05.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1178">1178</ref>
    </refs>
    <vuln_soft>
      <prod name="dbman" vendor="gossamer_threads">
        <vers num="2.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0382" seq="2000-0382" published="2000-05-08" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=15697&amp;Method=Full" adv="1" patch="1">ASB00-12</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1179">1179</ref>
    </refs>
    <vuln_soft>
      <prod name="clustercats" vendor="allaire">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0383" seq="2000-0383" published="2000-05-08" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1180">1180</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=002401bfb918$7310d5a0$1ef084ce@karemor.com">20000507 AOL Instant Messenger</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0384" seq="2000-0384" published="2000-05-08" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://216.188.41.136/">http://216.188.41.136/</ref>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/ipivot7180.html" adv="1" patch="1">20000508 NetStructure 7110 console backdoor</ref>
      <ref source="L0PHT" url="http://www.lopht.com/advisories/ipivot7110.html" adv="1" patch="1">20000508 NetStructure 7180 remote backdoor vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1182" adv="1" patch="1">1182</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1183" adv="1" patch="1">1183</ref>
    </refs>
    <vuln_soft>
      <prod name="netstructure_7110" vendor="intel">
        <vers num=""/>
      </prod>
      <prod name="netstructure_7180" vendor="intel">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0385" seq="2000-0385" published="2000-05-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html">http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html</ref>
      <ref source="CONFIRM" url="http://www.filemaker.com/support/webcompanion.html">http://www.filemaker.com/support/webcompanion.html</ref>
    </refs>
    <vuln_soft>
      <prod name="filemaker" vendor="filemaker">
        <vers num="5.0" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0386" seq="2000-0386" published="2000-05-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html">http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html</ref>
      <ref source="CONFIRM" url="http://www.filemaker.com/support/webcompanion.html">http://www.filemaker.com/support/webcompanion.html</ref>
    </refs>
    <vuln_soft>
      <prod name="filemaker" vendor="filemaker">
        <vers num="5.0" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0387" seq="2000-0387" published="2000-05-09" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:16.golddig.asc">FreeBSD-SA-00:16</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1184">1184</ref>
    </refs>
    <vuln_soft>
      <prod name="golddig" vendor="alexander_siegel">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0388" seq="2000-0388" published="1990-05-09" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A17.libmytinfo.asc">FreeBSD-SA-00:17</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1185">1185</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0389" seq="2000-0389" published="2000-05-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html" adv="1">CA-2000-06</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num="4.0"/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num="5.0"/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0390" seq="2000-0390" published="2000-05-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html" adv="1">CA-2000-06</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num="4.0"/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num="5.0"/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0391" seq="2000-0391" published="2000-05-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html" adv="1">CA-2000-06</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num="4.0"/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num="5.0"/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0392" seq="2000-0392" published="2000-05-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html" adv="1">CA-2000-06</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num="4.0"/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num="5.0"/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0393" seq="2000-0393" published="2000-05-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0172.html">20000516 kscd vulnerability</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_50.html">20000529 kmulti &lt;= 1.1.2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1206">1206</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="2.0_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0394" seq="2000-0394" published="2000-05-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signature.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95878603510835&amp;w=2">20000519 RFP2K05: NetProwler vs. RFProwler</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1225">1225</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=392AD3B3.3E9BE3EA@axent.com">20000522 RFP2K05 - NetProwler "Fragmentation" Issue</ref>
    </refs>
    <vuln_soft>
      <prod name="netprowler" vendor="axent">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0395" seq="2000-0395" published="2000-05-16" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1213">1213</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=007d01bfbf48$e44f0e40$01dc11ac@peopletel.org">20000516 CProxy v3.3 SP 2 DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="cproxy_server" vendor="computalynx">
        <vers num="3.3sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0396" seq="2000-0396" published="2000-05-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0285.html">20000524 Alert: Carello File Creation flaw</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1245">1245</ref>
    </refs>
    <vuln_soft>
      <prod name="carello" vendor="pacific_software">
        <vers num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0397" seq="2000-0397" published="2000-05-15" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0160.html">20000515 Vulnerability in EMURL-based e-mail providers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1203">1203</ref>
    </refs>
    <vuln_soft>
      <prod name="emurl" vendor="seattle_lab_software">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0398" seq="2000-0398" published="2000-05-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0286.html">20000524 Alert: Buffer overflow in Rockliffe's MailSite</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1244">1244</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsite" vendor="rockliffe">
        <vers num="4.2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0399" seq="2000-0399" published="2000-05-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0301.html">20000524 Deerfield Communications MDaemon Mail Server DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1250">1250</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="3.0.3"/>
        <vers num="3.1_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0400" seq="2000-0400" published="2000-05-13" modified="2016-11-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95868514521257&amp;w=2">20000516 MICROSOFT SECURITY FLAW?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1221">1221</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_explorer" vendor="microsoft">
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0401" seq="2000-0401" published="2000-05-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95928319715983&amp;w=2">20000525 Alert: PDG Cart Overflows</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=95928667119963&amp;w=2">20000525 Alert: PDG Cart Overflows</ref>
      <ref source="CONFIRM" url="http://www.pdgsoft.com/Security/security2.html">http://www.pdgsoft.com/Security/security2.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1256">1256</ref>
    </refs>
    <vuln_soft>
      <prod name="pdg_shopping_cart" vendor="pdgsoft">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0402" seq="2000-0402" published="2000-05-30" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=263968">Q263968</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1281">1281</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-035">MS00-035</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0403" seq="2000-0403" published="2000-05-25" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=263307">Q263307</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1261">1261</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-036">MS00-036</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0404" seq="2000-0404" published="2000-05-25" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=262694">Q262694</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1262">1262</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-036">MS00-036</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0405" seq="2000-0405" published="2000-05-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/asniff_advisory.txt" adv="1" patch="1">20000515 AntiSniff version 1.01 and Researchers version 1 DNS overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1207">1207</ref>
    </refs>
    <vuln_soft>
      <prod name="antisniff" vendor="atstake">
        <vers num="1.0" edition=":researchers"/>
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0406" seq="2000-0406" published="2000-05-10" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-05.html" adv="1">CA-2000-05</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-028.html">RHSA-2000:028</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1188">1188</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
        <vers num="4.05"/>
        <vers num="4.5_beta"/>
        <vers num="4.06"/>
        <vers num="4.07"/>
        <vers num="4.51"/>
        <vers num="4.61"/>
        <vers num="4.72"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0407" seq="2000-0407" published="2000-05-12" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0141.html">20000512 New Solaris root exploit for /usr/lib/lp/bin/netpr</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1200">1200</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0408" seq="2000-0408" published="2000-05-11" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=260205">Q260205</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1190">1190</ref>
      <ref source="MISC" url="http://www.ussrback.com/labs40.html">http://www.ussrback.com/labs40.html</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-030">MS00-030</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0409" seq="2000-0409" published="2000-05-10" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0126.html">20000510 Possible symlink problems with Netscape 4.73</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1201">1201</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.51"/>
        <vers num="4.61"/>
        <vers num="4.72"/>
        <vers num="4.73"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0410" seq="2000-0410" published="2000-05-10" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0005&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=4843" adv="1" patch="1">20000510 Cold Fusion Server 4.5.1 DoS Vulnerability.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1192">1192</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="4.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0411" seq="2000-0411" published="2000-05-10" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0125.html">20000510 Black Watch Labs Vulnerability Alert</ref>
      <ref source="MISC" url="http://www.perfectotech.com/blackwatchlabs/vul5_10.html">http://www.perfectotech.com/blackwatchlabs/vul5_10.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1187">1187</ref>
    </refs>
    <vuln_soft>
      <prod name="formmail" vendor="matt_wright">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0412" seq="2000-0412" published="1999-05-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:18-gnapster.adv">FreeBSD-SA-00:18</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0124.html">20000510 KNapster Vulnerability Compromises User-readable Files</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0127.html">20000510 Gnapster Vulnerability Compromises User-readable Files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1186">1186</ref>
    </refs>
    <vuln_soft>
      <prod name="knapster" vendor="napster">
        <vers num="napster"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0413" seq="2000-0413" published="2000-05-06" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html">20000506 shtml.exe reveal local path of IIS web directory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1174">1174</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0414" seq="2000-0414" published="2000-05-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0047.html">HPSBUX0005-113</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1214">1214</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
      <prod name="vvos" vendor="hp">
        <vers num="10.24"/>
        <vers num="11.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0415" seq="2000-0415" published="2000-05-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0140.html">20000512 Overflow in Outlook Express 4.* - too long filenames with graphic format extension</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1195" adv="1" patch="1">1195</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="98"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.01"/>
        <vers num="4.27.3110.1"/>
        <vers num="4.72.2106.4"/>
        <vers num="4.72.3120.0"/>
        <vers num="4.72.3612.1700"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0416" seq="2000-0416" published="2000-05-11" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm">http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1196">1196</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NABBJLKKPKIHDIMKFKGCMEFANMAB.georger@nls.net">20000511 NTMail Proxy Exploit</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0417" seq="2000-0417" published="2000-05-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0075.html">20000505 Cayman 3220-H DSL Router DOS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1219">1219</ref>
    </refs>
    <vuln_soft>
      <prod name="3220-h_dsl_router" vendor="cayman">
        <vers num="1.0"/>
      </prod>
      <prod name="gatorsurf" vendor="cayman">
        <vers num="5.3build_r1"/>
        <vers num="5.3build_r2"/>
        <vers num="5.5build_r0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0418" seq="2000-0418" published="2000-05-23" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1240">1240</ref>
    </refs>
    <vuln_soft>
      <prod name="3220-h_dsl_router" vendor="cayman">
        <vers num="1.0"/>
      </prod>
      <prod name="gatorsurf" vendor="cayman">
        <vers num="5.3"/>
        <vers num="5.3build_r1"/>
        <vers num="5.3build_r2"/>
        <vers num="5.5build_r0"/>
        <vers num="5.5build_r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0419" seq="2000-0419" published="2000-05-11" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-07.html">CA-2000-07</ref>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=262767">Q262767</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1197">1197</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-034">MS00-034</ref>
    </refs>
    <vuln_soft>
      <prod name="access" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="excel" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="frontpage" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="office" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="photodraw_2000" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
      <prod name="powerpoint" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="project" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="works" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0420" seq="2000-0420" published="2000-05-11" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0112.html">20000511 ISS SAVANT Advisory 00/26</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1198">1198</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0421" seq="2000-0421" published="2000-05-11" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0128.html">20000510 Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1199">1199</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0422" seq="2000-0422" published="2000-05-04" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95749276827558&amp;w=2">20000504 Alert: DMailWeb buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1171">1171</ref>
    </refs>
    <vuln_soft>
      <prod name="dmail" vendor="netwin">
        <vers num="2.5d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0423" seq="2000-0423" published="2000-05-05" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95764950403250&amp;w=2">20000505 Alert: DNewsWeb buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1172">1172</ref>
    </refs>
    <vuln_soft>
      <prod name="dnews" vendor="netwin">
        <vers num="5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0424" seq="2000-0424" published="2000-05-15" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1202">1202</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005151024.aa01811@blaze.arl.mil">20000514 Vulnerability in CGI counter 4.0.7 by George Burgyan</ref>
    </refs>
    <vuln_soft>
      <prod name="cgi_counter" vendor="george_burgyan">
        <vers num="4.0.2"/>
        <vers num="4.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0425" seq="2000-0425" published="2000-05-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0048.html">20000505 Alert: Listserv Web Archives (wa) buffer overflow</ref>
      <ref source="CONFIRM" url="http://www.lsoft.com/news/default.asp?item=Advisory0">http://www.lsoft.com/news/default.asp?item=Advisory0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1167">1167</ref>
    </refs>
    <vuln_soft>
      <prod name="listserv" vendor="lsoft">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0426" seq="2000-0426" published="2000-05-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0059.html">20000505 Re: Fun with UltraBoard V1.6X</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1175">1175</ref>
    </refs>
    <vuln_soft>
      <prod name="ultraboard" vendor="ultrascripts">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0427" seq="2000-0427" published="2000-05-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/etoken-piepa.txt">20000504 eToken Private Information Extraction and Physical Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1170">1170</ref>
    </refs>
    <vuln_soft>
      <prod name="etoken" vendor="aladdin_knowledge_systems">
        <vers num="3.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0428" seq="2000-0428" published="2000-05-04" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/39_Trend.asp">20000503 Trend Micro InterScan VirusWall Remote Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1168">1168</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.0.1"/>
        <vers num="3.2.3"/>
        <vers num="3.3"/>
        <vers num="3.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0429" seq="2000-0429" published="2000-04-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95686068203138&amp;w=2">20000427 Alert: Cart32 secret password backdoor (CISADV000427)</ref>
      <ref source="CONFIRM" url="http://www.cart32.com/kbshow.asp?article=c048">http://www.cart32.com/kbshow.asp?article=c048</ref>
    </refs>
    <vuln_soft>
      <prod name="cart32" vendor="mcmurtrey_whitaker_and_associates">
        <vers num="2.6"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0430" seq="2000-0430" published="2000-05-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95738697301956&amp;w=2">20000503 Another interesting Cart32 command</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1358">1358</ref>
    </refs>
    <vuln_soft>
      <prod name="cart32" vendor="mcmurtrey_whitaker_and_associates">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0431" seq="2000-0431" published="2000-05-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html">http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1238" adv="1" patch="1">1238</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000523100045.B11049@HiWAAY.net">20000522  Problem with FrontPage on Cobalt RaQ2/RaQ3</ref>
    </refs>
    <vuln_soft>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0432" seq="2000-0432" published="2000-05-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0173.html">20000516 Vuln in calender.pl (Matt Kruse calender script)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1215">1215</ref>
    </refs>
    <vuln_soft>
      <prod name="calendar_script" vendor="matt_kruse">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0433" seq="2000-0433" published="2000-05-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_47.html">20000502 aaabase &lt; 2000.5.2</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1" edition="alpha"/>
        <vers num="6.2"/>
        <vers num="6.3" edition=":ppc"/>
        <vers num="6.3" edition="alpha"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0434" seq="2000-0434" published="2000-05-13" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html">20000516 Allmanage.pl Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1217">1217</ref>
    </refs>
    <vuln_soft>
      <prod name="allmanage" vendor="matthew_redman">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0435" seq="2000-0435" published="2000-05-13" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html">20000516 Allmanage.pl Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1217">1217</ref>
    </refs>
    <vuln_soft>
      <prod name="allmanage" vendor="matthew_redman">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0436" seq="2000-0436" published="2000-05-19" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0254.html">20000522 MetaProducts Offline Explorer Directory Traversal Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.metaproducts.com/mpOE-HY.html" patch="1">http://www.metaproducts.com/mpOE-HY.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1231">1231</ref>
    </refs>
    <vuln_soft>
      <prod name="offline_explorer" vendor="metaproducts">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0437" seq="2000-0437" published="2000-05-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0249.html">20000522 Gauntlet CyberPatrol Buffer Overflow</ref>
      <ref source="CONFIRM" url="http://www.pgp.com/jump/gauntlet_advisory.asp">http://www.pgp.com/jump/gauntlet_advisory.asp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1234">1234</ref>
      <ref source="CONFIRM" url="http://www.tis.com/support/cyberadvisory.html">http://www.tis.com/support/cyberadvisory.html</ref>
    </refs>
    <vuln_soft>
      <prod name="gauntlet_firewall" vendor="network_associates">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.5"/>
      </prod>
      <prod name="webshield" vendor="network_associates">
        <vers num="4.0" edition=":solaris"/>
      </prod>
      <prod name="webshield_e-ppliance" vendor="network_associates">
        <vers num="100.0"/>
        <vers num="300.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0438" seq="2000-0438" published="2000-05-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0245.html">20000522 fdmount buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1239">1239</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="7.0"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.4.1"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0439" seq="2000-0439" published="2000-05-11" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1194">1194</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000511135609.D7774@securityfocus.com">20000510 IE Domain Confusion Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NDBBKGHPMKBKDDGLDEEHAEHMDIAA.rms2000@bellatlantic.net">20000511 IE Domain Confusion Vulnerability is an Email problem also</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-033">MS00-033</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4447">ie-cookie-disclosure(4447)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="3.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0440" seq="2000-0440" published="2000-05-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-002.txt.asc">NetBSD-SA2000-002</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0088.html">20000506 [NHC20000504a.0: NetBSD Panics when sent unaligned IP options]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1173">1173</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.4"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0441" seq="2000-0441" published="2000-05-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="IBM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0275.html">ERS-OAR-E01-2000:087.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1241">1241</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0442" seq="2000-0442" published="2000-05-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0267.html">20000523 Qpopper 2.53 remote problem, user can gain gid=mail</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_51.html">20000608 pop &lt;= 2000.3.4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1242">1242</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="2.52"/>
        <vers num="2.53"/>
      </prod>
      <prod name="cobalt_raq_2" vendor="sun">
        <vers num=""/>
      </prod>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0443" seq="2000-0443" published="2000-05-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0281.html">20000524 HP Web JetAdmin Version 5.6 Web interface Server Directory Traversal Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1243">1243</ref>
    </refs>
    <vuln_soft>
      <prod name="jetadmin" vendor="hp">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0444" seq="2000-0444" published="2000-05-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0277.html">20000524 HP Web JetAdmin Version 6.0 Remote DoS attack Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1246">1246</ref>
    </refs>
    <vuln_soft>
      <prod name="jetadmin" vendor="hp">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0445" seq="2000-0445" published="2000-05-24" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0273.html">20000523 Key Generation Security Flaw in PGP 5.0</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-09.html">CA-2000-09</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1251">1251</ref>
    </refs>
    <vuln_soft>
      <prod name="pgp" vendor="pgp">
        <vers num="5.0_linux"/>
        <vers num="5.0i"/>
        <vers num="6.5_linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0446" seq="2000-0446" published="2000-05-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0274.html">20000524 Remote xploit for MDBMS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1252">1252</ref>
    </refs>
    <vuln_soft>
      <prod name="mdbms" vendor="marty_bochane">
        <vers num="0.9_xbx"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0447" seq="2000-0447" published="2000-05-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1254">1254</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool</ref>
    </refs>
    <vuln_soft>
      <prod name="webshield" vendor="network_associates">
        <vers num="4.5.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0448" seq="2000-0448" published="2000-05-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1253">1253</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool</ref>
    </refs>
    <vuln_soft>
      <prod name="webshield" vendor="network_associates">
        <vers num="4.5.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0449" seq="2000-0449" published="2000-05-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0311.html">20000525 Omnis Weak Encryption - Many products affected</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1255">1255</ref>
    </refs>
    <vuln_soft>
      <prod name="studio" vendor="omnis">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0450" seq="2000-0450" published="2000-05-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0216.html">20000518 FW: Security Notice: Big Brother System and Network Monitor</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1257">1257</ref>
    </refs>
    <vuln_soft>
      <prod name="big_brother" vendor="sean_macguire">
        <vers num="1.3b"/>
        <vers num="1.4"/>
        <vers num="1.4g"/>
        <vers num="1.4h1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0451" seq="2000-0451" published="2000-05-19" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0229.html">20000518 Remote Dos attack against Intel express 8100 router</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1228">1228</ref>
    </refs>
    <vuln_soft>
      <prod name="express_8100" vendor="intel">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0452" seq="2000-0452" published="2000-05-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0219.html">20000518 Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl))</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1229">1229</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_enterprise_server" vendor="lotus">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
      </prod>
      <prod name="domino_mail_server" vendor="lotus">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0453" seq="2000-0453" published="2000-05-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-012.0.txt">CSSA-2000-012.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0223.html">20000518 Nasty XFree Xserver DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1235">1235</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0454" seq="2000-0454" published="2000-05-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0367.html">20000527 Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0434.html">20000603 [Gael Duval ] [Security Announce] cdrecord</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0019.html">20000607 Conectiva Linux Security Announcement - cdrecord</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1265">1265</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0455" seq="2000-0455" published="2000-05-29" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memory via a long -mode option.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-003.txt.asc">NetBSD-SA2000-003</ref>
      <ref source="TURBO" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0375.html">TLSA2000012-1</ref>
      <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/41initialized.asp">20000529 Initialized Data Overflow in Xlock</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1267">1267</ref>
    </refs>
    <vuln_soft>
      <prod name="xlock" vendor="david_bagley">
        <vers num="4.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0456" seq="2000-0456" published="2000-05-28" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka "cpu-hog".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-005.txt.asc">NetBSD-SA2000-005</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1272">1272</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1" edition=":alpha"/>
        <vers num="1.4.1" edition=":arm32"/>
        <vers num="1.4.1" edition=":sparc"/>
        <vers num="1.4.1" edition=":x86"/>
        <vers num="1.4.2" edition=":alpha"/>
        <vers num="1.4.2" edition=":arm32"/>
        <vers num="1.4.2" edition=":sparc"/>
        <vers num="1.4.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0457" seq="2000-0457" published="2000-05-11" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95810120719608&amp;w=2">20000511 Alert: IIS ism.dll exposes file contents</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1193">1193</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-031">MS00-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4448">iis-ism-file-access(4448)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0458" seq="2000-0458" published="2000-04-22" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95672120116627&amp;w=2">20000424 Two Problems in IMP 2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1360">1360</ref>
    </refs>
    <vuln_soft>
      <prod name="imp" vendor="imp">
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.2_pre9"/>
        <vers num="2.2_pre10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0459" seq="2000-0459" published="2000-04-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95672120116627&amp;w=2">20000424 Two Problems in IMP 2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1361">1361</ref>
    </refs>
    <vuln_soft>
      <prod name="imp" vendor="imp">
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.2_pre9"/>
        <vers num="2.2_pre10"/>
        <vers num="2.2_pre11"/>
        <vers num="2.2_pre12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0460" seq="2000-0460" published="2000-05-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0353.html" adv="1">20000526 KDE: /usr/bin/kdesud, gid = 0 exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1274">1274</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0461" seq="2000-0461" published="2000-05-29" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:19.semconfig.asc">FreeBSD-SA-00:19</ref>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-004.txt.asc">NetBSD-SA2000-004</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata26.html#semconfig">20000526</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1270">1270</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.1.5.1"/>
        <vers num="2.0"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.6.1"/>
        <vers num="2.1.7.1"/>
        <vers num="2.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1" edition=":alpha"/>
        <vers num="1.4.1" edition=":arm32"/>
        <vers num="1.4.1" edition=":sparc"/>
        <vers num="1.4.2" edition=":alpha"/>
        <vers num="1.4.2" edition=":arm32"/>
        <vers num="1.4.2" edition=":sparc"/>
        <vers num="1.4.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0462" seq="2000-0462" published="2000-05-28" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-006.txt.asc">NetBSD-SA2000-006</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1273">1273</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.2" edition=":alpha"/>
        <vers num="1.4.2" edition=":arm32"/>
        <vers num="1.4.2" edition=":sparc"/>
        <vers num="1.4.2" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0463" seq="2000-0463" published="2000-05-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BeOS 5.0 allows remote attackers to cause a denial of service via fragmented TCP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0197.html">20000517 AUX Security Advisory on Be/OS 5.0 (DoS)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1222">1222</ref>
    </refs>
    <vuln_soft>
      <prod name="beos" vendor="be">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0464" seq="2000-0464" published="2000-05-17" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the "Malformed Component Attribute" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=261257">Q261257</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1223">1223</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-033">MS00-033</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0465" seq="2000-0465" published="2000-05-17" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x does not properly verify the domain of a  frame within a browser window, which allows a remote attacker to read client files via the frame, aka the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=251108">Q251108</ref>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=255676">Q255676</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1224">1224</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-033">MS00-033</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
        <vers num="5.5" edition="preview"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0466" seq="2000-0466" published="2000-06-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AIX cdmount allows local users to gain root privileges via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1384" adv="1" patch="1">1384</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise55.php" adv="1">20000620 Insecure call of external program in AIX cdmount</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0467" seq="2000-0467" published="2000-06-01" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0125.html" adv="1" patch="1">20000614 Splitvt exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1346">1346</ref>
    </refs>
    <vuln_soft>
      <prod name="splitvt" vendor="sam_lantinga">
        <vers num="1.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0468" seq="2000-0468" published="2000-06-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1302" adv="1" patch="1">1302</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SOL.4.02.10006021014400.4779-100000@nofud.nwest.attws.com">20000601 HP Security vulnerability in the man command</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0469" seq="2000-0469" published="2000-02-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1347">1347</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-22&amp;msg=ILENKALMCAFBLHBGEOFKGEJCCAAA.jwesterink@jwesterink.daxis.nl" adv="1" patch="1">20000613 CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.2.0.58.20000620193604.00979950@mail.clark.net">20000620 Re: CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="webbanner" vendor="selena_sol">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0470" seq="2000-0470" published="2000-06-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0398.html">20000601 Hardware Exploit - Gets network Down</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1290">1290</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4588">rompager-malformed-dos(4588)</ref>
    </refs>
    <vuln_soft>
      <prod name="rom_pager" vendor="allegro">
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0471" seq="2000-0471" published="2000-06-14" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0114.html">20000614 Vulnerability in Solaris ufsrestore</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/210">00210</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/36866">VU#36866</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1348" adv="1" patch="1">1348</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4711">sol-ufsrestore-bo(4711)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="" edition=":x86"/>
        <vers num="1.1.3" edition="u1"/>
        <vers num="1.1.4" edition=":jl"/>
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="5.4" edition=":x86"/>
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
        <vers num="5.6" edition=":x86"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.6"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0472" seq="2000-0472" published="2000-02-06" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-016.0.txt">CSSA-2000-016.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0003.html">20000106 innd 2.2.2 remote buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0097.html">20000707 inn update</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0298.html">20000721 [ANNOUNCE] INN 2.2.3 available</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0330.html">20000722 MDKSA-2000:023 inn update</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1316">1316</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4615">innd-cancel-overflow(4615)</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0473" seq="2000-0473" published="2000-06-15" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm" patch="1">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1349" adv="1" patch="1">1349</ref>
    </refs>
    <vuln_soft>
      <prod name="simpleserver_www" vendor="analogx">
        <vers num="1.01"/>
        <vers num="1.03"/>
        <vers num="1.04"/>
        <vers num="1.05"/>
        <vers num="1.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0474" seq="2000-0474" published="2000-06-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0410.html">20000601 Remote DoS attack in Real Networks Real Server (Strike #2) Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0427.html">20000601 Remote DoS attack in RealServer: USSR-2000043</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1288" adv="1" patch="1">1288</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4587">realserver-malformed-remote-dos(4587)</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver" vendor="realnetworks">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
        <vers num="8.0_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0475" seq="2000-0475" published="2000-06-15" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desktop Separation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1350" adv="1" patch="1">1350</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-020">MS00-020</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4714">win2k-desktop-separation(4714)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0476" seq="2000-0476" published="2000-06-01" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0409.html" adv="1" patch="1">20000601 [rootshell.com] Xterm DoS Attack</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0420.html">20000601 [rootshell.com] Xterm DoS Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1298" adv="1" patch="1">1298</ref>
    </refs>
    <vuln_soft>
      <prod name="eterm" vendor="michael_jennings">
        <vers num="0.8.10"/>
      </prod>
      <prod name="putty" vendor="putty">
        <vers num="0.48"/>
      </prod>
      <prod name="rxvt" vendor="rxvt">
        <vers num="2.6.1"/>
      </prod>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.3"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0477" seq="2000-0477" published="2000-06-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1351" adv="1" patch="1">1351</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4710">antivirus-nav-zip-bo(4710)</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="1.5" edition=":ms_exchange"/>
        <vers num="2.0" edition=":ms_exchange"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0478" seq="2000-0478" published="2000-06-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1351" adv="1">1351</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4709">antivirus-nav-fail-open(4709)</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="1.5" edition=":ms_exchange"/>
        <vers num="2.0" edition=":ms_exchange"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0479" seq="2000-0479" published="2000-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Dragon FTP server allows remote attackers to cause a denial of service via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96113734714517&amp;w=2">20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1352" adv="1">1352</ref>
    </refs>
    <vuln_soft>
      <prod name="dragon_server" vendor="shadow_op_software">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0480" seq="2000-0480" published="2000-06-16" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Dragon telnet server allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96113734714517&amp;w=2">20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1352" adv="1">1352</ref>
    </refs>
    <vuln_soft>
      <prod name="dragon_server" vendor="shadow_op_software">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0481" seq="2000-0481" published="1999-06-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://securityfocus.com/templates/archive.pike?list=82&amp;date=2000-06-22&amp;msg=00060200422401.01667@lez" adv="1">20000601 Kmail heap overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1380" adv="1" patch="1">1380</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4993">kde-kmail-attachment-dos(4993)</ref>
    </refs>
    <vuln_soft>
      <prod name="k-mail" vendor="kde">
        <vers num="1.0.23"/>
        <vers num="1.0.24"/>
        <vers num="1.0.25"/>
        <vers num="1.0.26"/>
        <vers num="1.0.27"/>
        <vers num="1.0.28"/>
        <vers num="1.0.29"/>
        <vers num="1.0.29.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0482" seq="2000-0482" published="2000-06-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0473.html">20000605 FW-1 IP Fragmentation Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation">http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1312" adv="1" patch="1">1312</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4609">fw1-packet-fragment-dos(4609)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0483" seq="2000-0483" published="2000-06-15" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A38.zope.asc">FreeBSD-SA-00:38</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0144.html" adv="1" patch="1">20000615 [Brian@digicool.com: [Zope] Zope security alert and 2.1.7 update [*important*]]</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0412.html">20000728 MDKSA-2000:026 Zope update</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-038.html">RHSA-2000:038</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1354">1354</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000616103807.A3768@conectiva.com.br">2000615 Conectiva Linux Security Announcement - ZOPE</ref>
      <ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert" patch="1">http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4716">zope-dtml-remote-modify(4716)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_powertools" vendor="redhat">
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
      <prod name="zope" vendor="zope">
        <vers num="1.10.3"/>
        <vers num="2.1.1"/>
        <vers num="2.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0484" seq="2000-0484" published="2000-06-15" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Small HTTP Server allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96113651713414&amp;w=2">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=96151775004229&amp;w=2">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1355">1355</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4692">small-http-get-overflow-dos(4692)</ref>
    </refs>
    <vuln_soft>
      <prod name="small_http_server" vendor="max_feoktistov">
        <vers num="1.212"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0485" seq="2000-0485" published="2000-05-30" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/62771">20000530 Fw: Steal Passwords Using SQL Server EM</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1292">1292</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-041">MS00-041</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4582">mssql-dts-reveal-passwords(4582)</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="6.5"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0486" seq="2000-0486" published="2000-05-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0369.html" adv="1" patch="1">20000530 An Analysis of the TACACS+ Protocol and its Implementations</ref>
      <ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html">http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1293">1293</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4985">tacacsplus-packet-length-dos(4985)</ref>
    </refs>
    <vuln_soft>
      <prod name="tacacs+" vendor="cisco">
        <vers num="f4.0.2alpha"/>
        <vers num="f4.0.3alpha"/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0487" seq="2000-0487" published="2000-06-01" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1295" adv="1" patch="1">1295</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-032">MS00-032</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0488" seq="2000-0488" published="2000-05-30" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0148.html" adv="1">20000601 DST2K0007: Buffer Overrun in ITHouse Mail Server v1.04</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1285">1285</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4580">ithouse-rcpt-overflow(4580)</ref>
    </refs>
    <vuln_soft>
      <prod name="ithouse_mail_server" vendor="ithouse">
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0489" seq="2000-0489" published="1999-09-05" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/622">622</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEJLCEAA.labs@ussrback.com">20000601 Local FreeBSD, Openbsd, NetBSD, DoS Vulnerability - Mac OS X affected</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9908270039010.16315-100000@thetis.deor.org">19990826 Local DoS in FreeBSD</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3298">bsd-setsockopt-dos(3298)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4" edition=":x86"/>
        <vers num="1.4.1" edition=":alpha"/>
        <vers num="1.4.1" edition=":arm32"/>
        <vers num="1.4.1" edition=":sparc"/>
        <vers num="1.4.1" edition=":x86"/>
        <vers num="1.4.2" edition=":alpha"/>
        <vers num="1.4.2" edition=":arm32"/>
        <vers num="1.4.2" edition=":sparc"/>
        <vers num="1.4.2" edition=":x86"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0490" seq="2000-0490" published="2000-06-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0407.html">20000601 Netwin's Dmail package</ref>
      <ref source="CONFIRM" url="http://netwinsite.com/dmail/security.htm">http://netwinsite.com/dmail/security.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1297" adv="1" patch="1">1297</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4579">dmail-etrn-dos(4579)</ref>
    </refs>
    <vuln_soft>
      <prod name="dmail" vendor="netwin">
        <vers num="2.7"/>
        <vers num="2.7q"/>
        <vers num="2.8e"/>
        <vers num="2.8f"/>
        <vers num="2.8g"/>
        <vers num="2.8h"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0491" seq="2000-0491" published="2000-05-24" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-013.0.txt" adv="1" patch="1">CSSA-2000-013.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0241.html">20000521 "gdm" remote hole</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0025.html">20000607 Conectiva Linux Security Announcement - gdm</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_49.html">20000524 Security hole in gdm &lt;= 2.0beta4-25</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1233">1233</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1279">1279</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1370">1370</ref>
    </refs>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="1.0"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.2"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0492" seq="2000-0492" published="2000-06-04" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0450.html" adv="1" patch="1">20000609 Insecure encryption in PassWD v1.2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1300">1300</ref>
    </refs>
    <vuln_soft>
      <prod name="passwd" vendor="passwd">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0493" seq="2000-0493" published="2000-06-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0843.html" adv="1">20000601 Vulnerability in SNTS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1289">1289</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4602">timesync-bo-execute(4602)</ref>
    </refs>
    <vuln_soft>
      <prod name="time_sync" vendor="atrius_trivalie_sn">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0494" seq="2000-0494" published="2000-06-16" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html" adv="1" patch="1">20000616 Veritas Volume Manager 3.0.x hole</ref>
      <ref source="CONFIRM" url="http://seer.support.veritas.com/tnotes/volumeman/230053.htm">http://seer.support.veritas.com/tnotes/volumeman/230053.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1356" adv="1" patch="1">1356</ref>
    </refs>
    <vuln_soft>
      <prod name="volume_manager" vendor="symantec_veritas">
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0495" seq="2000-0495" published="2000-05-30" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1282">1282</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-038">MS00-038</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4585">ms-malformed-media-dos(4585)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_services" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0497" seq="2000-0497" published="2000-06-08" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0263.html" adv="1" patch="1">20000612 IBM WebSphere JSP showcode vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1328">1328</ref>
      <ref source="CONFIRM" url="http://www-4.ibm.com/software/webservers/appserv/efix.html">http://www-4.ibm.com/software/webservers/appserv/efix.html</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="3.0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0498" seq="2000-0498" published="2000-06-08" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0250.html" adv="1">20000608 Potential vulnerability in Unify eWave ServletExec</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1328">1328</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4649">ewave-servletexec-jsp-source-read(4649)</ref>
    </refs>
    <vuln_soft>
      <prod name="ewave_servletexec" vendor="unify">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0499" seq="2000-0499" published="2000-06-08" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0262.htm">20000612 BEA WebLogic JSP showcode vulnerability</ref>
      <ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000612.html">http://developer.bea.com/alerts/security_000612.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1328" adv="1" patch="1">1328</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4694">weblogic-jsp-source-read(4694)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="" edition=":express"/>
        <vers num="3.1.8"/>
        <vers num="4.0.4"/>
        <vers num="4.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0500" seq="2000-0500" published="2000-06-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96161462915381&amp;w=2">20000621 BEA WebLogic /file/ showcode vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1378" adv="1" patch="1">1378</ref>
      <ref source="CONFIRM" url="http://www.weblogic.com/docs51/admindocs/http.html#file">http://www.weblogic.com/docs51/admindocs/http.html#file</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4775">weblogic-file-source-read(4775)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="3.1.8" edition=":express"/>
        <vers num="4.0" edition=":express"/>
        <vers num="4.5" edition=":express"/>
        <vers num="5.1" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0501" seq="2000-0501" published="2000-06-16" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0277.html" adv="1" patch="1">20000616 mdaemon 2.8.5.0 WinNT and Win9x remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1366">1366</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4745">mdaemon-pass-dos(4745)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="2.8.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0502" seq="2000-0502" published="2000-06-08" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Server, which allows local users to modify alerts in an arbitrary fashion.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0038.html" adv="1">20000607 Mcafee Alerting DOS vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1326" adv="1">1326</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4641">mcafee-alerting-dos(4641)</ref>
    </refs>
    <vuln_soft>
      <prod name="virusscan" vendor="mcafee">
        <vers num="4.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0503" seq="2000-0503" published="2000-06-06" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0154.html" adv="1" patch="1">20000606 IE 5 Cross-frame security vulnerability using IFRAME and WebBrowser control</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1311">1311</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
        <vers num="5.5" edition="preview"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0504" seq="2000-0504" published="2000-06-19" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0170.html" adv="1">20000619 XFree86: libICE DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1369" adv="1" patch="1">1369</ref>
      <ref source="CONFIRM" url="http://www.xfree86.org/security/">http://www.xfree86.org/security/</ref>
    </refs>
    <vuln_soft>
      <prod name="gdm" vendor="gnome">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="x" vendor="open_group">
        <vers num="11.0r5"/>
        <vers num="11.0r6"/>
        <vers num="11.0r6.1"/>
        <vers num="11.0r6.2"/>
        <vers num="11.0r6.3"/>
        <vers num="11.0r6.4"/>
      </prod>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0505" seq="2000-0505" published="2000-05-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1284" adv="1" patch="1">1284</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.20.0006031912360.45740-100000@alive.znep.com" adv="1" patch="1">20000603 Re: IBM HTTP SERVER / APACHE</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4575">ibm-http-file-retrieve(4575)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.6" edition=":win32"/>
        <vers num="1.3.9" edition=":win32"/>
        <vers num="1.3.11" edition=":win32"/>
        <vers num="1.3.12" edition=":win32"/>
      </prod>
      <prod name="http_server" vendor="ibm">
        <vers num="1.3.3" edition=":win32"/>
        <vers num="1.3.6.2" edition=":win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0506" seq="2000-0506" published="2000-06-09" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://sgigate.sgi.com/security/20000802-01-P">20000802-01-P</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0062.html">20000609 Trustix Security Advisory</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0063.html">20000608 CONECTIVA LINUX SECURITY ANNOUNCEMENT - kernel</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-037.html">RHSA-2000:037</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1322">1322</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006090852340.3475-300000@alfa.elzabsoft.pl" adv="1">20000609 Sendmail &amp; procmail local root exploits on Linux kernel up to 2.2.16pre5</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0"/>
        <vers num="2.0.30"/>
        <vers num="2.0.33"/>
        <vers num="2.0.34"/>
        <vers num="2.0.35"/>
        <vers num="2.0.36"/>
        <vers num="2.0.37"/>
        <vers num="2.0.38"/>
        <vers num="2.1"/>
        <vers num="2.2.0"/>
        <vers num="2.2.10"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.15_pre20"/>
        <vers num="2.2.16" edition="pre5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0507" seq="2000-0507" published="2000-06-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95990195708509&amp;w=2">20000601 DST2K0006: Denial of Service Possibility in Imate WebMail Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1286" adv="1">1286</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4586">nt-webmail-dos(4586)</ref>
    </refs>
    <vuln_soft>
      <prod name="imate_webmail_server" vendor="concatus">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0508" seq="2000-0508" published="1994-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0073.html" adv="1" patch="1">20000608 Remote DOS in linux rpc.lockd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1372" adv="1" patch="1">1372</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5050">linux-lockd-remote-dos(5050)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0509" seq="2000-0509" published="2000-06-01" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95990103207665&amp;w=2">20000601 DST2K0008: Buffer Overrun in Sambar Server 4.3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1287" adv="1" patch="1">1287</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="4.3" prev="1" edition="beta9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0510" seq="2000-0510" published="2000-06-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" adv="1" patch="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1373" adv="1">1373</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4846">debian-cups-malformed-ipp(4846)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0511" seq="2000-0511" published="2000-06-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" adv="1" patch="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1373" adv="1">1373</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4846">debian-cups-posts(4846)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0512" seq="2000-0512" published="2000-06-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" adv="1" patch="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1373" adv="1">1373</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4846">debian-cups-posts(4846)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0513" seq="2000-0513" published="2000-06-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch" adv="1" patch="1">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1373">1373</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4846">debian-cups-posts(4846)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0514" seq="2000-0514" published="2000-06-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/ftp.txt" adv="1" patch="1">http://web.mit.edu/kerberos/www/advisories/ftp.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1374">1374</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=ldvsnufao18.fsf@saint-elmos-fire.mit.edu">20000614 Security Advisory: REMOTE ROOT VULNERABILITY IN GSSFTP DAEMON</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4734">kerberos-gssftpd-dos(4734)</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0515" seq="2000-0515" published="2000-06-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1327">1327</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006070511.OAA05492@dogfoot.hackerslab.org">20000607 [ Hackerslab bug_paper ] HP-UX SNMP daemon vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006090640.XAA00779@hpchs.cup.hp.com">20000608 Re: HP-UX SNMP daemon vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4643">hpux-snmp-daemon(4643)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0516" seq="2000-0516" published="2000-06-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0008.html" adv="1" patch="1">20000606 Shiva Access Manager 5.0.0 Plaintext LDAP root password.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1329">1329</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4612">shiva-plaintext-ldap-password(4612)</ref>
    </refs>
    <vuln_soft>
      <prod name="shiva_access_manager" vendor="intel">
        <vers num="5.0" edition=":solaris"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0517" seq="2000-0517" published="2000-05-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-08.html" adv="1" patch="1">CA-2000-08</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1260" adv="1" patch="1">1260</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4550">netscape-ssl-certificate(4550)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.51"/>
        <vers num="4.61"/>
        <vers num="4.72"/>
        <vers num="4.73"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0518" seq="2000-0518" published="2000-06-05" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different "SSL Certificate Validation" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-10.html" adv="1" patch="1">CA-2000-10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1309" adv="1" patch="1">1309</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-039">MS00-039</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4624">ie-invalid-frame-image-certificate(4624)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0" edition=":windows_98"/>
        <vers num="4.0" edition=":windows_nt"/>
        <vers num="4.0.1" edition=":windows_95"/>
        <vers num="4.0.1" edition=":windows_98"/>
        <vers num="4.0.1" edition=":windows_nt"/>
        <vers num="5" edition=":windows_nt_4.0"/>
        <vers num="5.0" edition=":windows_2000"/>
        <vers num="5.0" edition=":windows_95"/>
        <vers num="5.0" edition=":windows_98"/>
        <vers num="5.0.1" edition=":windows_2000"/>
        <vers num="5.0.1" edition=":windows_95"/>
        <vers num="5.0.1" edition=":windows_98"/>
        <vers num="5.0.1" edition=":windows_nt_4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0519" seq="2000-0519" published="2000-06-05" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-10.html" adv="1" patch="1">CA-2000-10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1309" adv="1" patch="1">1309</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-039">MS00-039</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4627">ie-revalidate-certificate(4627)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0" edition=":windows_98"/>
        <vers num="4.0" edition=":windows_nt"/>
        <vers num="4.0.1" edition=":windows_95"/>
        <vers num="4.0.1" edition=":windows_98"/>
        <vers num="4.0.1" edition=":windows_nt"/>
        <vers num="5.0" edition=":windows_2000"/>
        <vers num="5.0" edition=":windows_95"/>
        <vers num="5.0" edition=":windows_98"/>
        <vers num="5.0" edition=":windows_nt_4.0"/>
        <vers num="5.0.1" edition=":windows_2000"/>
        <vers num="5.0.1" edition=":windows_95"/>
        <vers num="5.0.1" edition=":windows_98"/>
        <vers num="5.0.1" edition=":windows_nt_4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0520" seq="2000-0520" published="2000-06-07" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880" adv="1" patch="1">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96240393814071&amp;w=2">20000630 CONECTIVA LINUX SECURITY ANNOUNCEMENT - dump</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1330" adv="1" patch="1">1330</ref>
    </refs>
    <vuln_soft>
      <prod name="pop_dump" vendor="stelian">
        <vers num="0.4b9.0"/>
        <vers num="0.4b9.9"/>
        <vers num="0.4b15.1"/>
        <vers num="0.4b15.30"/>
        <vers num="0.4b16.0"/>
        <vers num="0.4b17.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0521" seq="2000-0521" published="2000-06-05" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0469.html" adv="1" patch="1">20000605 MDMA Advisory #5: Reading of CGI Scripts under Savant Webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1313" adv="1" patch="1">1313</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4616">savant-source-read(4616)</ref>
    </refs>
    <vuln_soft>
      <prod name="savant_webserver" vendor="michael_lamont">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0522" seq="2000-0522" published="2000-06-08" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.securid.com/support/outgoing/dos/readme.txt" adv="1" patch="1">ftp://ftp.securid.com/support/outgoing/dos/readme.txt</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0197.html" adv="1" patch="1">20000714 Re: RSA Aceserver UDP Flood Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1332" adv="1" patch="1">1332</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=011a01bfd14c$3c206960$050010ac@xtranet.co.uk">20000608 Potential DoS Attack on RSA's ACE/Server</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5053">aceserver-udp-packet-dos(5053)</ref>
    </refs>
    <vuln_soft>
      <prod name="ace_server" vendor="rsa">
        <vers num="3.1"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0523" seq="2000-0523" published="2000-06-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0009.html" adv="1">20000606 MDMA Advisory #6: EServ Logging Heap Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1315" adv="1">1315</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4614">eserv-logging-overflow(4614)</ref>
    </refs>
    <vuln_soft>
      <prod name="eserv" vendor="etype">
        <vers num="2.9.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0524" seq="2000-0524" published="2000-06-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0045.html" adv="1">20000604 Microsoft Outlook (Express) bug..</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1333" adv="1">1333</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num="97"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0525" seq="2000-0525" published="2000-06-08" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.html">20000609 OpenSSH's UseLogin option allows remote access with root privilege.</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata.html#uselogin">20000606 The non-default UseLogin feature in /etc/sshd_config is broken and should not be used.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1334">1334</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4646">openssh-uselogin-remote-exec(4646)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2"/>
        <vers num="1.2.3"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0526" seq="2000-0526" published="2000-06-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html" adv="1">20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1335" adv="1">1335</ref>
    </refs>
    <vuln_soft>
      <prod name="mailstudio_2000" vendor="3r_soft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0527" seq="2000-0527" published="2000-06-09" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html">20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1335" adv="1">1335</ref>
    </refs>
    <vuln_soft>
      <prod name="mailstudio_2000" vendor="3r_soft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0528" seq="2000-0528" published="2000-06-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Net Tools PKI Server does not properly restrict access to remote attackers when the XUDA template files do not contain absolute pathnames for other files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html" adv="1" patch="1">20000619 Net Tools PKI server exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1364" adv="1" patch="1">1364</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4743">nettools-pki-unauthenticated-access(4743)</ref>
    </refs>
    <vuln_soft>
      <prod name="net_tools_pki_server" vendor="network_associates">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0529" seq="2000-0529" published="2000-06-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Net Tools PKI Server allows remote attackers to cause a denial of service via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html" adv="1" patch="1">20000619 Net Tools PKI server exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1363" adv="1" patch="1">1363</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4744">nettools-pki-http-bo(4744)</ref>
    </refs>
    <vuln_soft>
      <prod name="net_tools_pki_server" vendor="network_associates">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0530" seq="2000-0530" published="2000-05-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-015.0.txt">CSSA-2000-015.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0387.html" adv="1" patch="1">20000531 KDE::KApplication feature?</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-032.html">RHSA-2000:032</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1291" adv="1" patch="1">1291</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4583">kde-configuration-file-creation(4583)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="kde" vendor="kde">
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0531" seq="2000-0531" published="1999-11-23" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0409.html">20000728 MDKSA:2000-025 gpm update</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-045.html">RHSA-2000:045</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1377" adv="1" patch="1">1377</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10006201453090.1812-200000@apollo.aci.com.pl" adv="1">20000620 Bug in gpm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5010">linux-gpm-gpmctl-dos(5010)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":i386"/>
        <vers num="6.1" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0532" seq="2000-0532" published="2000-06-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-06/0031.html" adv="1" patch="1">FreeBSD-SA-00:21</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1323" adv="1" patch="1">1323</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4638">freebsd-ssh-ports(4638)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0533" seq="2000-0533" published="2000-06-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://sgigate.sgi.com/security/20000601-01-P">20000601-01-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1379" adv="1" patch="1">1379</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4725">irix-workshop-cvconnect-overwrite(4725)</ref>
    </refs>
    <vuln_soft>
      <prod name="workshop_debugger_and_performance_tools" vendor="sgi">
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0534" seq="2000-0534" published="2000-06-07" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows local users to execute commands as the lpd user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1325" adv="1" patch="1">1325</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4617">apsfilter-elevate-privileges(4617)</ref>
    </refs>
    <vuln_soft>
      <prod name="apsfilter" vendor="aps_filter_development_team">
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0535" seq="2000-0535" published="2000-06-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-06/0083.html" adv="1" patch="1">FreeBSD-SA-00:25</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1340" adv="1" patch="1">1340</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.4"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0" edition="alpha"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0536" seq="2000-0536" published="2000-06-04" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000619">20000619 xinetd: bug in access control mechanism</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1381" adv="1" patch="1">1381</ref>
      <ref source="CONFIRM" url="http://www.synack.net/xinetd/" adv="1" patch="1">http://www.synack.net/xinetd/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4986">xinetd-improper-restrictions(4986)</ref>
    </refs>
    <vuln_soft>
      <prod name="xinetd" vendor="xinetd">
        <vers num="2.1.87"/>
        <vers num="2.1.88"/>
        <vers num="2.1.88_pre1"/>
        <vers num="2.1.88_pre2"/>
        <vers num="2.1.89_pre1"/>
        <vers num="2.1.89_pre2"/>
        <vers num="2.1.89_pre3"/>
        <vers num="2.1.89_pre4"/>
        <vers num="2.1.89_pre5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0537" seq="2000-0537" published="2000-06-05" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0013.html" adv="1">20000606 BRU Vulnerability</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-018.0.txt">CSSA-2000-018.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1321" adv="1" patch="1">1321</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4644">bru-execlog-env-variable(4644)</ref>
    </refs>
    <vuln_soft>
      <prod name="bru" vendor="tolis_group">
        <vers num="15.1"/>
        <vers num="16.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0538" seq="2000-0538" published="2000-06-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96045469627806&amp;w=2">20000607 New Allaire ColdFusion DoS</ref>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=16122&amp;Method=Full" adv="1" patch="1">ASB00-14</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1314" adv="1" patch="1">1314</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4611">coldfusion-parse-dos(4611)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.01"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.5"/>
        <vers num="4.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0539" seq="2000-0539" published="2000-06-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full" adv="1" patch="1">ASB00-015</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1386" adv="1" patch="1">1386</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4774">jrun-read-sample-files(4774)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0540" seq="2000-0540" published="2000-06-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full" adv="1" patch="1">ASB00-015</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1386" adv="1" patch="1">1386</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4774">jrun-read-sample-files(4774)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0541" seq="2000-0541" published="2000-06-17" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0164.html" adv="1" patch="1">20000617 Infosec.20000617.panda.a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1359" adv="1" patch="1">1359</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4707">panda-antivirus-remote-admin(4707)</ref>
    </refs>
    <vuln_soft>
      <prod name="panda_antivirus" vendor="panda">
        <vers num="2.0" edition=":netware"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0542" seq="2000-0542" published="2000-06-13" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0104.html" adv="1">20000612 ACC/Ericsson Tigris Accounting Failure</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1345" adv="1" patch="1">1345</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4705">tigris-radius-login-failure(4705)</ref>
    </refs>
    <vuln_soft>
      <prod name="axc_tigris_multiservice_access_platform" vendor="ericsson">
        <vers num="623.0"/>
        <vers num="627.0"/>
        <vers num="711.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0543" seq="2000-0543" published="2000-06-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not have a reverse DNS entry and they connect to port 4000.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0107.html" adv="1" patch="1">20000614 Remote DoS attack in Networks Associates PGP Certificate Server Version 2.5 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1343" adv="1" patch="1">1343</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4695">pgp-cert-server-dos(4695)</ref>
    </refs>
    <vuln_soft>
      <prod name="certificate_server" vendor="pgp">
        <vers num="2.5"/>
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0544" seq="2000-0544" published="2000-06-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0231.html" adv="1">20000604 anonymous SMBwriteX DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1304" adv="1">1304</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0545" seq="2000-0545" published="2000-08-08" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0435.html" adv="1">20000602 /usr/bin/Mail exploit for Slackware 7.0 (mail-slack.c)</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000605">20000605 mailx: mail group exploit in mailx</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1305">1305</ref>
    </refs>
    <vuln_soft>
      <prod name="mailx" vendor="sgi">
        <vers num="3"/>
        <vers num="4"/>
        <vers num="5"/>
        <vers num="6.0.1"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0546" seq="2000-0546" published="2000-06-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" adv="1" patch="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html" adv="1" patch="1">CA-2000-11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1338">1338</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num=""/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num=""/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0" prev="1"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0547" seq="2000-0547" published="2000-06-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" adv="1" patch="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html" adv="1" patch="1">CA-2000-11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1338">1338</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num=""/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num=""/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0" prev="1"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0548" seq="2000-0548" published="2000-06-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" adv="1" patch="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html" adv="1" patch="1">CA-2000-11</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num=""/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num=""/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0" prev="1"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0549" seq="2000-0549" published="2000-06-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html" adv="1" patch="1">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html" adv="1" patch="1">CA-2000-11</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num="4.0"/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num="5.0"/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0"/>
        <vers num="5-1.1"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0550" seq="2000-0550" published="2000-06-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html" adv="1" patch="1">CA-2000-11</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1465">1465</ref>
    </refs>
    <vuln_soft>
      <prod name="cygnus_network_security" vendor="cygnus">
        <vers num="4.0"/>
      </prod>
      <prod name="kerbnet" vendor="cygnus">
        <vers num="5.0"/>
      </prod>
      <prod name="kerberos" vendor="mit">
        <vers num="4.0"/>
        <vers num="5-1.1"/>
        <vers num="5_1.0"/>
        <vers num="5_1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0551" seq="2000-0551" published="2000-05-23" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The file transfer mechanism in Danware NetOp 6.0 does not provide authentication, which allows remote attackers to access and modify arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0339.html" adv="1">20000523 I think</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1263" adv="1" patch="1">1263</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4569">danware-netop-bypass-security(4569)</ref>
    </refs>
    <vuln_soft>
      <prod name="netop" vendor="danware_data">
        <vers num="6.0"/>
        <vers num="6.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0552" seq="2000-0552" published="2000-06-06" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0237.html" adv="1" patch="1">20000606 ICQ2000A ICQmail temparary internet link vulnearbility</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1307" adv="1" patch="1">1307</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4607">icq-temp-link(4607)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="2000.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0553" seq="2000-0553" published="2000-05-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0326.html" adv="1" patch="1">20000525 Security Vulnerability in IPFilter 3.3.15 and 3.4.3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1308" adv="1" patch="1">1308</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4994">ipfilter-firewall-race-condition(4994)</ref>
    </refs>
    <vuln_soft>
      <prod name="ipfilter" vendor="darren_reed">
        <vers num="3.3.15"/>
        <vers num="3.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0554" seq="2000-0554" published="2000-06-08" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html" adv="1" patch="1">20000608 DST2K0010: DoS &amp; Path Revealing Vulnerability in Ceilidh v2.60a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1320" adv="1">1320</ref>
    </refs>
    <vuln_soft>
      <prod name="ceilidh" vendor="lilikoi">
        <vers num="2.60"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0555" seq="2000-0555" published="2000-06-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html" adv="1" patch="1">20000608 DST2K0010: DoS &amp; Path Revealing Vulnerability in Ceilidh v2.60a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1320" adv="1">1320</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4622">ceilidh-post-dos(4622)</ref>
    </refs>
    <vuln_soft>
      <prod name="ceilidh" vendor="lilikoi">
        <vers num="2.60"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0556" seq="2000-0556" published="2000-06-05" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html" adv="1" patch="1">20000608 DST2K0011: DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref>
      <ref source="CONFIRM" url="http://www.computalynx.net/news/Jun2000/news0806200001.html">http://www.computalynx.net/news/Jun2000/news0806200001.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1319" adv="1" patch="1">1319</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4625">cmail-long-username-dos(4625)</ref>
    </refs>
    <vuln_soft>
      <prod name="cmail" vendor="computalynx">
        <vers num="2.4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0557" seq="2000-0557" published="2000-06-05" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html" adv="1" patch="1">20000608 DST2K0011: DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1318" adv="1" patch="1">1318</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4626">cmail-get-overflow-execute(4626)</ref>
    </refs>
    <vuln_soft>
      <prod name="cmail" vendor="computalynx">
        <vers num="2.4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0558" seq="2000-0558" published="2000-06-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0249.html" adv="1">20000608 DST2K0012: BufferOverrun in HP Openview Network Node Manager v6.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1317" adv="1">1317</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0559" seq="2000-0559" published="2000-06-07" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1341" adv="1" patch="1">1341</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSO.4.21.0006072124320.28062-100000@bearclaw.bogus.net">20000607 SessionWall-3 Paper + (links to) code</ref>
    </refs>
    <vuln_soft>
      <prod name="etrust_intrusion_detection" vendor="ca">
        <vers num="1.4.1.13" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0561" seq="2000-0561" published="2000-06-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0175.html" adv="1" patch="1">20000620 DST2K0018: Multiple BufferOverruns in WebBBS HTTP Server v1.15</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1365" adv="1" patch="1">1365</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4742">webbbs-get-request-overflow(4742)</ref>
    </refs>
    <vuln_soft>
      <prod name="international_telecommunications_webbbs" vendor="international_telecommunications">
        <vers num="1.1.5"/>
        <vers num="1.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0562" seq="2000-0562" published="2000-06-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0190.html" adv="1" patch="1">20000620 BlackICE by Network ICE Corp vulnerability against Back Orifice 1.2</ref>
    </refs>
    <vuln_soft>
      <prod name="blackice_agent" vendor="iss">
        <vers num="2.0.23" prev="1"/>
      </prod>
      <prod name="blackice_defender" vendor="iss">
        <vers num="2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0563" seq="2000-0563" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0056.html" adv="1" patch="1">20000609 Security Holes Found in URLConnection of MRJ and IE of Mac OS (was Re: Reappearance of an old IE security bug)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1336">1336</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-05-8&amp;msg=391C95DE2DA.5E3BTAKAGI@java-house.etl.go.jp">20000513 Re: Reappearance of an old IE security bug</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_runtime_for_java" vendor="apple">
        <vers num="2.1" prev="1" edition=":java"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0564" seq="2000-0564" published="2000-05-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0218.html" adv="1" patch="1">20000529 ICQ Web Front Remote DoS Attack Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="0.99b_1.1.1.1"/>
        <vers num="0.99b_v.3.19"/>
        <vers num="98.0a"/>
        <vers num="99a_2.15build1701"/>
        <vers num="99a_2.21build1800"/>
        <vers num="2000.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0565" seq="2000-0565" published="2000-06-13" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0100.html" adv="1" patch="1">20000613 SmartFTP Daemon v0.2 Beta Build 9 - Remote Exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1344" adv="1" patch="1">1344</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4706">smartftp-directory-traversal(4706)</ref>
    </refs>
    <vuln_soft>
      <prod name="smartftp_daemon" vendor="mindstorm">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0566" seq="2000-0566" published="2000-07-03" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">makewhatis in Linux man package allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt">CSSA-2000-021.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0390.html">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - MAN</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:015">MDKSA-2000:015</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-041.html">RHSA-2000:041</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1434">1434</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4900">linux-man-makewhatis-tmp(4900)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2" edition=":alpha"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="5.2" edition=":sparc"/>
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0567" seq="2000-0567" published="2000-07-18" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the "Malformed E-mail Header" vulnerability.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1481">1481</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-043">MS00-043</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4953">outlook-date-overflow(4953)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="97"/>
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.01"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0568" seq="2000-0568" published="2000-06-30" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1417">1417</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4125690E.00524395.00@guardianit.se" adv="1">20000630 Multiple vulnerabilities in Sybergen Secure Desktop</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_desktop" vendor="sybergen">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0569" seq="2000-0569" published="2000-06-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0189.html" adv="1" patch="1">20000630 Any LAN user can crash Sygate</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1420" adv="1" patch="1">1420</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5049">sygate-udp-packet-dos(5049)</ref>
    </refs>
    <vuln_soft>
      <prod name="sygate" vendor="sybergen">
        <vers num="2.0"/>
        <vers num="3.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0570" seq="2000-0570" published="2000-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0295.html" adv="1">20000627 DoS in FirstClass Internet Services 5.770</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1421" adv="1">1421</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4843">firstclass-large-bcc-dos(4843)</ref>
    </refs>
    <vuln_soft>
      <prod name="firstclass_intranet_server" vendor="centrinity">
        <vers num="5.770"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0571" seq="2000-0571" published="2000-07-05" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1423">1423</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-07-8&amp;msg=NCBBKFKDOLAGKIAPMILPCEIHCFAA.labs@ussrback.com" adv="1">20000703 Remote DoS Attack in LocalWEB HTTP Server 1.2.0 Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4896">localweb-get-bo(4896)</ref>
    </refs>
    <vuln_soft>
      <prod name="localweb_http_server" vendor="west_street_software">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0572" seq="2000-0572" published="2000-07-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1424">1424</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-07-8&amp;msg=613309F30B6DD2118C020000F809376C05CABD49@emss03m09.orl.lmco.com" adv="1" patch="1">20000704 Recovering Passwords in Visible Systems' Razor</ref>
    </refs>
    <vuln_soft>
      <prod name="razor" vendor="visible_systems">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0573" seq="2000-0573" published="2000-07-07" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.02">AA-2000.02</ref>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:29.wu-ftpd.asc.v1.1">FreeBSD-SA-00:29</ref>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-009.txt.asc">NetBSD-SA2000-009</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0244.html">20000723 CONECTIVA LINUX SECURITY ANNOUNCEMENT - WU-FTPD (re-release)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0017.html">20000702 [Security Announce] wu-ftpd update</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96171893218000&amp;w=2">20000622 WuFTPD: Providing *remote* root since at least1994</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96179429114160&amp;w=2">20000623 WUFTPD 2.6.0 remote root exploit</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96299933720862&amp;w=2">20000707 New Released Version of the WuFTPD Sploit</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-020.0.txt">CSSA-2000-020.0</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-13.html" adv="1" patch="1">CA-2000-13</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-039.html">RHSA-2000:039</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1387">1387</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000623091822.3321.qmail@fiver.freemessage.com">20000623 ftpd: the advisory version</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4773">wuftp-format-string-stack-overwrite(4773)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0574" seq="2000-0574" published="2000-07-07" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-009.txt.asc">NetBSD-SA2000-009</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0031.html">20000705 proftp advisory</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0061.html">20000706 ftpd and setproctitle()</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0121.html">20000710 opieftpd setproctitle() patches</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-13.html" adv="1" patch="1">CA-2000-13</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1425">1425</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1438">1438</ref>
    </refs>
    <vuln_soft>
      <prod name="ftpd" vendor="openbsd">
        <vers num="5.51"/>
        <vers num="5.60"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4.2_beta1" edition=":academ"/>
        <vers num="2.4.2_beta18" edition=":academ"/>
        <vers num="2.4.2_beta18_vr4"/>
        <vers num="2.4.2_beta18_vr5"/>
        <vers num="2.4.2_beta18_vr6"/>
        <vers num="2.4.2_beta18_vr7"/>
        <vers num="2.4.2_beta18_vr8"/>
        <vers num="2.4.2_beta18_vr9"/>
        <vers num="2.4.2_beta18_vr10"/>
        <vers num="2.4.2_beta18_vr11"/>
        <vers num="2.4.2_beta18_vr12"/>
        <vers num="2.4.2_beta18_vr13"/>
        <vers num="2.4.2_beta18_vr14"/>
        <vers num="2.4.2_beta18_vr15"/>
        <vers num="2.4.2_vr16"/>
        <vers num="2.4.2_vr17"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0575" seq="2000-0575" published="2000-07-05" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96256265914116&amp;w=2">20000630 Kerberos security vulnerability in SSH-1.2.27</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1426" adv="1" patch="1">1426</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4903">ssh-kerberos-tickets-disclosure(4903)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.27"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0576" seq="2000-0576" published="2000-07-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0027.html" adv="1">20000704 Oracle Web Listener for AIX DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1427" adv="1">1427</ref>
    </refs>
    <vuln_soft>
      <prod name="web_listener" vendor="oracle">
        <vers num="4.0.7" edition=":aix"/>
        <vers num="4.0.8" edition=":aix"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0577" seq="2000-0577" published="2000-06-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0345.html">20000629 (forw) Re: Netscape ftp Server (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1411">1411</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211351280.23780-100000@nimue.tpi.pl" adv="1" patch="1">20000621 Netscape FTP Server - "Professional" as hell :></ref>
    </refs>
    <vuln_soft>
      <prod name="professional_services_ftpserver" vendor="netscape">
        <vers num="1.3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0578" seq="2000-0578" published="2000-06-21" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html" adv="1">20000621 Predictability Problems in IRIX Cron and Compilers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1412" adv="1">1412</ref>
    </refs>
    <vuln_soft>
      <prod name="mipspro_compilers" vendor="sgi">
        <vers num="7.1"/>
        <vers num="7.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0579" seq="2000-0579" published="2000-06-21" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user's crontab file as it is being edited.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html" adv="1">20000621 Predictability Problems in IRIX Cron and Compilers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1413" adv="1">1413</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.3"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0580" seq="2000-0580" published="2000-06-30" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1415" adv="1">1415</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630161935.4619B-100000@fjord.fscinternet.com" adv="1">20000630 SecureXpert Advisory [SX-20000620-2]</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="2000.0.2195"/>
        <vers num="2000.2072"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0581" seq="2000-0581" published="2000-06-30" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1414">1414</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630161841.4619A-100000@fjord.fscinternet.com" adv="1">20000630 SecureXpert Advisory [SX-20000620-1]</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="2000.0.2195"/>
        <vers num="2000.2031"/>
        <vers num="2000.2072"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0582" seq="2000-0582" published="2000-06-30" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security">http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1416">1416</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630162106.4619C-100000@fjord.fscinternet.com" adv="1">20000630 SecureXpert Advisory [SX-20000620-3]</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0583" seq="2000-0583" published="2000-06-30" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1418">1418</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=395BD2A8.5D3396A7@secureaustin.com" adv="1">20000626 vpopmail-3.4.11 problems</ref>
      <ref source="CONFIRM" url="http://www.vpopmail.cx/vpopmail-ChangeLog">http://www.vpopmail.cx/vpopmail-ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod name="vpopmail_vchkpw" vendor="inter7">
        <vers num="4.5"/>
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0584" seq="2000-0584" published="2000-07-02" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:31.canna.asc.v1.1">FreeBSD-SA-00:31</ref>
      <ref source="MISC" url="http://shadowpenguin.backsection.net/advisories/advisory038.html">http://shadowpenguin.backsection.net/advisories/advisory038.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1445">1445</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4912">canna-bin-execute-bo(4912)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0585" seq="2000-0585" published="2000-06-24" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:34.dhclient.asc">FreeBSD-SA-00:34</ref>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-008.txt.asc">NetBSD-SA2000-008</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0247.html" adv="1" patch="1">20000624 Possible root exploit in ISC DHCP client.</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0014.html">20000702 [Security Announce] dhcp update</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000628">20000628 dhcp client: remote root exploit in dhcp client</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_56.html">20000711 Security Hole in dhclient &lt; 2.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1388">1388</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4772">openbsd-isc-dhcp(4772)</ref>
    </refs>
    <vuln_soft>
      <prod name="dhcp_client" vendor="isc">
        <vers num="2.0"/>
        <vers num="3.0b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0586" seq="2000-0586" published="2000-06-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/1092.html">20000628 dalnet 4.6.5 remote vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1404">1404</ref>
    </refs>
    <vuln_soft>
      <prod name="ircd" vendor="dalnet">
        <vers num="4.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0587" seq="2000-0587" published="2000-06-26" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0317.html">20000627 Re: Glftpd privpath bugs... +fix</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1401">1401</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10006261041360.31907-200000@twix.thrijswijk.nl" adv="1" patch="1">20000626 Glftpd privpath bugs... +fix</ref>
    </refs>
    <vuln_soft>
      <prod name="glftpd" vendor="glftpd">
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.20"/>
        <vers num="1.21b1"/>
        <vers num="1.21b2"/>
        <vers num="1.21b3"/>
        <vers num="1.21b4"/>
        <vers num="1.21b5"/>
        <vers num="1.21b6"/>
        <vers num="1.21b7"/>
        <vers num="1.21b8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0588" seq="2000-0588" published="2000-06-26" modified="2013-07-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html" adv="1">20000626 sawmill5.0.21 old path bug &amp; weak hash algorithm</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html">20000706 Patch for Flowerfire Sawmill Vulnerabilities Available</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1402">1402</ref>
    </refs>
    <vuln_soft>
      <prod name="sawmill" vendor="sawmill">
        <vers num="5.0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0589" seq="2000-0589" published="2000-06-26" modified="2013-07-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html" adv="1" patch="1">20000626 sawmill5.0.21 old path bug &amp; weak hash algorithm</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html">20000706 Patch for Flowerfire Sawmill Vulnerabilities Available</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1403">1403</ref>
    </refs>
    <vuln_soft>
      <prod name="sawmill" vendor="sawmill">
        <vers num="5.0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0590" seq="2000-0590" published="2000-07-04" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0076.html" adv="1" patch="1">20000706 Vulnerability in Poll_It cgi v2.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1431" adv="1" patch="1">1431</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4878">http-cgi-pollit-variable-overwrite(4878)</ref>
    </refs>
    <vuln_soft>
      <prod name="poll_it" vendor="cgi-world">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0591" seq="2000-0591" published="2000-07-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0038.html" adv="1">20000705 Novell BorderManager 3.0 EE - Encoded URL rule bypass</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1432">1432</ref>
    </refs>
    <vuln_soft>
      <prod name="bordermanager" vendor="novell">
        <vers num="3.0"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0592" seq="2000-0592" published="2000-06-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1400">1400</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006271417.GFE84146.-BJXON@lac.co.jp" adv="1" patch="1">20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="sapporoworks_winproxy" vendor="sapporoworks">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0593" seq="2000-0593" published="2000-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1400">1400</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006271417.GFE84146.-BJXON@lac.co.jp">20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4831">winproxy-get-dos(4831)</ref>
    </refs>
    <vuln_soft>
      <prod name="sapporoworks_winproxy" vendor="sapporoworks">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0594" seq="2000-0594" published="2000-07-04" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0026.html">20000704 BitchX exploit possibly waiting to happen, certain DoS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0098.html">20000707 CONECTIVA LINUX SECURITY ANNOUNCEMENT - BitchX</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0105.html">20000707 BitchX update</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-07/0042.html">FreeBSD-SA-00:32</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0018.html">20000704 BitchX /ignore bug</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-022.0.txt">CSSA-2000-022.0</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-042.html">RHSA-2000:042</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1436">1436</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4897">irc-bitchx-invite-dos(4897)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_desktop" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="openlinux_ebuilder" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5"/>
        <vers num="4.0"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="2007"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0595" seq="2000-0595" published="2000-07-05" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-07/0035.html" adv="1" patch="1">FreeBSD-SA-00:24</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1437" adv="1" patch="1">1437</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0596" seq="2000-0596" published="2000-06-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the "IE Script" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-16.html">CA-2000-16</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1398">1398</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000d01bfe0fb$418f59b0$96217aa8@src.bu.edu">20000627 FW: IE 5 and Access 2000 vulnerability - executing programs</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589359.762392DB@nat.bg" adv="1" patch="1">20000627 IE 5 and Access 2000 vulnerability - executing programs</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-049">MS00-049</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0.1" edition="sp2"/>
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0597" seq="2000-0597" published="2000-06-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1399">1399</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589349.ED9DBCAB@nat.bg" adv="1" patch="1">20000627 IE 5 and Excel 2000, PowerPoint 2000 vulnerability - executing programs</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-049">MS00-049</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="powerpoint" vendor="microsoft">
        <vers num="97"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0598" seq="2000-0598" published="2000-06-26" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0268.html" adv="1" patch="1">20000626 Proxy+ Telnet Gateway Problems</ref>
      <ref source="MISC" url="http://www.proxyplus.cz/faq/articles/EN/art01002.htm">http://www.proxyplus.cz/faq/articles/EN/art01002.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1395">1395</ref>
    </refs>
    <vuln_soft>
      <prod name="proxy+" vendor="fortech">
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0599" seq="2000-0599" published="2000-06-29" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0335.html" adv="1" patch="1">20000629 iMesh 1.02 vulnerability</ref>
      <ref source="MISC" url="http://www.imesh.com/download/download.html">http://www.imesh.com/download/download.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1407">1407</ref>
    </refs>
    <vuln_soft>
      <prod name="imesh" vendor="imesh.com">
        <vers num="1.02" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0600" seq="2000-0600" published="2000-06-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0264.html" adv="1" patch="1">20000626 Netscape Enterprise Server for NetWare Virtual Directory Vulnerab ility</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1393" adv="1" patch="1">1393</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4780">netscape-virtual-directory-bo(4780)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="4.1.1" edition=":netware"/>
        <vers num="5.0" edition=":netware"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0601" seq="2000-0601" published="2000-06-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.leafdigital.com/Software/leafChat/history.html">http://www.leafdigital.com/Software/leafChat/history.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1396">1396</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.10.10006252056110.74551-100000@unix.za.net" adv="1">20000625 LeafChat Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod name="leafchat" vendor="leafdigital">
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0602" seq="2000-0602" published="2000-06-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1385">1385</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl">20000621 rh 6.2 - gid compromises, etc</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_locate" vendor="kevin_lindsay">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0603" seq="2000-0603" published="2000-07-07" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the "Stored Procedure Permissions" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1444" adv="1" patch="1">1444</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-048">MS00-048</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4921">mssql-procedure-perms(4921)</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0604" seq="2000-0604" published="2000-06-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1383" adv="1">1383</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl" adv="1">20000621 rh 6.2 - gid compromises, etc</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0605" seq="2000-0605" published="2000-07-10" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=NTBUGTRAQ&amp;P=R1647">20000710 Two issues: Blackboard CourseInfo 4.0 stores admin password in clear text; strange settings on the winreg key.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1460">1460</ref>
    </refs>
    <vuln_soft>
      <prod name="courseinfo" vendor="blackboard">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0606" seq="2000-0606" published="2000-06-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1371">1371</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk" adv="1">20000619 Problems with "kon2" package</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0607" seq="2000-0607" published="2000-06-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1371">1371</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk" adv="1">20000619 Problems with "kon2" package</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0608" seq="2000-0608" published="2000-06-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1376" adv="1" patch="1">1376</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-15&amp;msg=4.1.20000621113334.00996820@qlink.queensu.ca" adv="1" patch="1">20000620 NetWin dMailWeb Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod name="cwmail" vendor="netwin">
        <vers num="2.5e"/>
        <vers num="2.6g"/>
        <vers num="2.6i"/>
        <vers num="2.6j"/>
      </prod>
      <prod name="dmailweb" vendor="netwin">
        <vers num="2.5e"/>
        <vers num="2.6g"/>
        <vers num="2.6i"/>
        <vers num="2.6j"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0609" seq="2000-0609" published="2000-06-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1376">1376</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-15&amp;msg=4.1.20000621113334.00996820@qlink.queensu.ca" adv="1">20000620 NetWin dMailWeb Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod name="cwmail" vendor="netwin">
        <vers num="2.5e"/>
        <vers num="2.6g"/>
        <vers num="2.6i"/>
        <vers num="2.6j"/>
      </prod>
      <prod name="dmailweb" vendor="netwin">
        <vers num="2.5e"/>
        <vers num="2.6g"/>
        <vers num="2.6i"/>
        <vers num="2.6j"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0610" seq="2000-0610" published="2000-06-23" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html">20000623 NetWin dMailWeb Unrestricted Mail Relay</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1390" adv="1" patch="1">1390</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4770">netwin-dmailweb-newline(4770)</ref>
    </refs>
    <vuln_soft>
      <prod name="cwmail" vendor="netwin">
        <vers num="2.6g"/>
      </prod>
      <prod name="dmailweb" vendor="netwin">
        <vers num="2.6g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0611" seq="2000-0611" published="2000-06-23" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html" adv="1" patch="1">20000623 NetWin dMailWeb Unrestricted Mail Relay</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1391" adv="1" patch="1">1391</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4771">netwin-dmailweb-auth(4771)</ref>
    </refs>
    <vuln_soft>
      <prod name="cwmail" vendor="netwin">
        <vers num="2.6g"/>
      </prod>
      <prod name="dmailweb" vendor="netwin">
        <vers num="2.6g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0612" seq="2000-0612" published="2000-06-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1406" adv="1">1406</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=395B7E64.9FB3D4DB@starzetz.de" adv="1">20000629 Buggy ARP handling in Windoze</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0613" seq="2000-0613" published="2000-03-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/pixtcpreset-pub.shtml">20000711 Cisco Secure PIX Firewall TCP Reset Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1454">1454</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=B3D6883199DBD311868100A0C9FC2CDC046B72@protea.citec.net" adv="1">20000320 PIX DMZ Denial of Service - TCP Resets</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4928">cisco-pix-firewall-tcp(4928)</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0614" seq="2000-0614" published="2000-07-10" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0002.html" adv="1" patch="1">20000710 Security Hole in tnef &lt; 0-124</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1450" adv="1" patch="1">1450</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3" edition=":ppc"/>
        <vers num="6.3" edition="alpha"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0615" seq="2000-0615" published="2000-07-19" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.html" adv="1" patch="1">20000709 LPRng lpd should not be SETUID root</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1447" adv="1" patch="1">1447</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7361">lpd-suid-root(7361)</ref>
    </refs>
    <vuln_soft>
      <prod name="lprng" vendor="astart_technologies">
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.5"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0616" seq="2000-0616" published="2000-06-26" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0294.html" adv="1" patch="1">HPSBMP0006-007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1405" adv="1" patch="1">1405</ref>
    </refs>
    <vuln_soft>
      <prod name="mpe_ix" vendor="hp">
        <vers num="4.5"/>
        <vers num="5.0"/>
        <vers num="5.5"/>
        <vers num="6.0"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0617" seq="2000-0617" published="2000-06-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html" adv="1">20000622 RHL 6.2 xconq package - overflows yield gid games</ref>
    </refs>
    <vuln_soft>
      <prod name="xconq" vendor="stanley_t._shebs">
        <vers num="7.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0618" seq="2000-0618" published="2000-06-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html" adv="1">20000622 RHL 6.2 xconq package - overflows yield gid games</ref>
    </refs>
    <vuln_soft>
      <prod name="xconq" vendor="stanley_t._shebs">
        <vers num="7.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0619" seq="2000-0619" published="2000-07-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0680.html" adv="1">20000520 TopLayer layer 7 switch Advisory</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0921.html" adv="1">20000614 Update on TopLayer Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1258" adv="1" patch="1">1258</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7364">toplayer-icmp-dos(7364)</ref>
    </refs>
    <vuln_soft>
      <prod name="appswitch" vendor="toplayer">
        <vers num="2500.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0620" seq="2000-0620" published="2000-06-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96146116627474&amp;w=2">20000619 XFree86: Various nasty libX11 holes</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1409" adv="1" patch="1">1409</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4996">libx11-infinite-loop-dos(4996)</ref>
    </refs>
    <vuln_soft>
      <prod name="x" vendor="open_group">
        <vers num="11.0r6"/>
        <vers num="11.0r6.1"/>
        <vers num="11.0r6.2"/>
        <vers num="11.0r6.3"/>
        <vers num="11.0r6.4"/>
      </prod>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.3"/>
        <vers num="3.3.4"/>
        <vers num="3.3.5"/>
        <vers num="3.3.6"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0621" seq="2000-0621" published="2000-07-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-14.html" adv="1" patch="1">CA-2000-14</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1501" adv="1" patch="1">1501</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-046">MS00-046</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5013">outlook-cache-bypass(5013)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="97"/>
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.01"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0622" seq="2000-0622" published="2000-07-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://website.oreilly.com/support/software/wspro25_releasenotes.txt">http://website.oreilly.com/support/software/wspro25_releasenotes.txt</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/043.asp">20000719 O'Reilly WebSite Professional Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1487">1487</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4962">website-webfind-bo(4962)</ref>
    </refs>
    <vuln_soft>
      <prod name="website_professional" vendor="oreilly">
        <vers num="2.3.18"/>
        <vers num="2.4"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0623" seq="2000-0623" published="2000-07-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5946" adv="1" patch="1">20000719 Alert: Buffer Overrun is O'Reilly WebsitePro httpd32.exe (CISADV000717)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1492" adv="1" patch="1">1492</ref>
    </refs>
    <vuln_soft>
      <prod name="website_professional" vendor="oreilly">
        <vers num="2.3.18"/>
        <vers num="2.4"/>
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0624" seq="2000-0624" published="2000-07-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0289.html" adv="1">20000720 Winamp M3U playlist parser buffer overflow security vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1496" adv="1">1496</ref>
      <ref source="CONFIRM" url="http://www.winamp.com/getwinamp/newfeatures.jhtml">http://www.winamp.com/getwinamp/newfeatures.jhtml</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4956">winamp-playlist-parser-bo(4956)</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="nullsoft">
        <vers num="2.64" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0625" seq="2000-0625" published="2000-07-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/netzero.txt" adv="1" patch="1">20000718 NetZero Password Encryption Algorithm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1483" adv="1" patch="1">1483</ref>
    </refs>
    <vuln_soft>
      <prod name="zeroport" vendor="netzero">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0626" seq="2000-0626" published="2000-07-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html" adv="1">20000718 Multiple bugs in Alibaba 2.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1482" adv="1">1482</ref>
    </refs>
    <vuln_soft>
      <prod name="alibaba" vendor="computer_software_manufaktur">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0627" seq="2000-0627" published="2000-07-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0254.html" adv="1">20000718 Blackboard Courseinfo v4.0 User Authentication</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1486" adv="1" patch="1">1486</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000719151904.I17986@securityfocus.com">20000719 Security Fix for Blackboard CourseInfo 4.0</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4946">blackboard-courseinfo-dbase-modification(4946)</ref>
    </refs>
    <vuln_soft>
      <prod name="courseinfo" vendor="blackboard">
        <vers num="4.0"/>
        <vers num="unix"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0628" seq="2000-0628" published="2000-07-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0142.html" adv="1" patch="1">20000710 ANNOUNCE Apache::ASP v1.95 - Security Hole Fixed</ref>
      <ref source="CONFIRM" url="http://www.nodeworks.com/asp/changes.html">http://www.nodeworks.com/asp/changes.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1457" adv="1" patch="1">1457</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4931">apache-source-asp-file-write(4931)</ref>
    </refs>
    <vuln_soft>
      <prod name="apache_asp" vendor="joshua_chamas">
        <vers num="0.16"/>
        <vers num="0.17"/>
        <vers num="0.18"/>
        <vers num="1.93"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0629" seq="2000-0629" published="2000-07-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0163.html" adv="1" patch="1">20000711 Sun's Java Web Server remote command execution vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1459">1459</ref>
      <ref source="MISC" url="http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html" adv="1" patch="1">http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html</ref>
    </refs>
    <vuln_soft>
      <prod name="java_system_web_server" vendor="sun">
        <vers num="1.1.3"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0630" seq="2000-0630" published="2000-07-17" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1488">1488</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-044">MS00-044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5104">iis-htr-obtain-code(5104)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0631" seq="2000-0631" published="2000-07-14" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96390444022878&amp;w=2">20000718 ISBASE Security Advisory(SA2000-02)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1476" adv="1" patch="1">1476</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-044">MS00-044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4951">iis-absent-directory-dos(4951)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0632" seq="2000-0632" published="2000-07-17" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.lsoft.com/news/default.asp?item=Advisory1">http://www.lsoft.com/news/default.asp?item=Advisory1</ref>
      <ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/43_Advisory.asp">20000717 [COVERT-2000-07] LISTSERV Web Archive Remote Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1490">1490</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4952">lsoft-listserv-querystring-bo(4952)</ref>
    </refs>
    <vuln_soft>
      <prod name="listserv" vendor="lsoft">
        <vers num="1.8c"/>
        <vers num="1.8d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0633" seq="2000-0633" published="2000-07-18" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0251.html" adv="1" patch="1">20000718 MDKSA-2000:020 usermode update</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0117.html">20000812 Conectiva Linux security announcement - usermode</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-053.html">RHSA-2000:053</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1489" adv="1" patch="1">1489</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4944">linux-usermode-dos(4944)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
        <vers num="6.2e" edition=":alpha"/>
        <vers num="6.2e" edition=":i386"/>
        <vers num="6.2e" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0634" seq="2000-0634" published="2000-04-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0223.html" adv="1" patch="1">20000717 S21SEC-003: Vulnerabilities in CommuniGate Pro v3.2.4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1493" adv="1" patch="1">1493</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5105">communigate-pro-file-read(5105)</ref>
    </refs>
    <vuln_soft>
      <prod name="communigate_pro" vendor="stalker">
        <vers num="3.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0635" seq="2000-0635" published="2000-07-10" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0150.html" adv="1">20000711 Akopia MiniVend Piped Command Execution Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1449" adv="1" patch="1">1449</ref>
      <ref source="CONFIRM" url="http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html">http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4880">minivend-viewpage-sample(4880)</ref>
    </refs>
    <vuln_soft>
      <prod name="minivend" vendor="akopia">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0636" seq="2000-0636" published="2000-07-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0265.html" adv="1" patch="1">20000719 HP Jetdirect - Invalid FTP Command DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1491" adv="1" patch="1">1491</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4947">hp-jetdirect-quote-dos(4947)</ref>
    </refs>
    <vuln_soft>
      <prod name="jetdirect" vendor="hp">
        <vers num="j3111a_rev._a.08.06"/>
        <vers num="j3111a_rev._g.05.35"/>
        <vers num="j3111a_rev._g.07.02"/>
        <vers num="j3111a_rev._g.07.03"/>
        <vers num="j3111a_rev._g.07.17"/>
        <vers num="j3111a_rev._g.08.03"/>
        <vers num="rev._g.08.04"/>
        <vers num="rev._g.08.20"/>
        <vers num="rev._h.08.05"/>
        <vers num="rev._h.08.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0637" seq="2000-0637" published="2000-07-26" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1451">1451</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396B3F8F.9244D290@nat.bg" adv="1" patch="1">20000711 Excel 2000 vulnerability - executing programs</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-051">MS00-051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5016">excel-register-function(5016)</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="97"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0638" seq="2000-0638" published="2000-07-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0146.html">20000711 BIG BROTHER EXPLOIT</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0147.html">20000711 REMOTE EXPLOIT IN ALL CURRENT VERSIONS OF BIG BROTHER</ref>
      <ref source="CONFIRM" url="http://bb4.com/README.CHANGES">http://bb4.com/README.CHANGES</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1455">1455</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4879">http-cgi-bigbrother-bbhostsvc(4879)</ref>
    </refs>
    <vuln_soft>
      <prod name="big_brother" vendor="sean_macguire">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3b"/>
        <vers num="1.4"/>
        <vers num="1.4g"/>
        <vers num="1.4h"/>
        <vers num="1.4h1"/>
        <vers num="1.09b"/>
        <vers num="1.09c"/>
        <vers num="1.09d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0639" seq="2000-0639" published="2000-06-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html" adv="1" patch="1">20000711 Big Brother filename extension vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1494" adv="1">1494</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5103">big-brother-filename-extension(5103)</ref>
    </refs>
    <vuln_soft>
      <prod name="big_brother" vendor="sean_macguire">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.3b"/>
        <vers num="1.4"/>
        <vers num="1.4g"/>
        <vers num="1.4h"/>
        <vers num="1.4h1"/>
        <vers num="1.09b"/>
        <vers num="1.09c"/>
        <vers num="1.09d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0640" seq="2000-0640" published="2000-07-08" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html" adv="1" patch="1">20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1452" adv="1">1452</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4922">guild-ftpd-disclosure(4922)</ref>
    </refs>
    <vuln_soft>
      <prod name="guildftpd" vendor="steve_poulsen">
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0641" seq="2000-0641" published="2000-07-08" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Savant web server allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html" adv="1">20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1453" adv="1">1453</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4901">savant-get-bo(4901)</ref>
    </refs>
    <vuln_soft>
      <prod name="savant_webserver" vendor="michael_lamont">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0642" seq="2000-0642" published="2000-07-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1497" adv="1">1497</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org" adv="1" patch="1">20000711 Lame DoS in WEBactive win65/NT server</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5184">webactive-active-log(5184)</ref>
    </refs>
    <vuln_soft>
      <prod name="webactive" vendor="itafrica">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0643" seq="2000-0643" published="2000-07-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1470" adv="1">1470</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org" adv="1">20000711 Lame DoS in WEBactive win65/NT server</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4949">webactive-long-get-dos(4949)</ref>
    </refs>
    <vuln_soft>
      <prod name="webactive" vendor="itafrica">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0644" seq="2000-0644" published="2000-07-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" adv="1" patch="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1506" adv="1" patch="1">1506</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5003">wftpd-stat-dos(5003)</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
        <vers num="2.4.1_rc11"/>
        <vers num="2.34"/>
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0645" seq="2000-0645" published="2000-07-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" adv="1" patch="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1506" adv="1" patch="1">1506</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
        <vers num="2.4.1_rc11"/>
        <vers num="2.34"/>
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0646" seq="2000-0646" published="2000-07-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" adv="1" patch="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1506" adv="1" patch="1">1506</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
        <vers num="2.4.1_rc11"/>
        <vers num="2.34"/>
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0647" seq="2000-0647" published="2000-07-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html" adv="1" patch="1">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1506" adv="1" patch="1">1506</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
        <vers num="2.4.1_rc11"/>
        <vers num="2.34"/>
        <vers num="2.40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0648" seq="2000-0648" published="2000-07-11" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1456" adv="1" patch="1">1456</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13BvU6-0007d8-00@dwarf.box.sk" adv="1">20000711 WFTPD/WFTPD Pro 2.41 RC10 denial-of-service</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0649" seq="2000-0649" published="2000-07-13" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0025.html" adv="1" patch="1">20000713 IIS4 Basic authentication realm issue</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1499" adv="1" patch="1">1499</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0650" seq="2000-0650" published="2000-07-11" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=2753" adv="1" patch="1">20000711 Potential Vulnerability in McAfee Netshield and VirusScan 4.5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1458" adv="1" patch="1">1458</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5177">nai-virusscan-netshield-autoupgrade(5177)</ref>
    </refs>
    <vuln_soft>
      <prod name="netshield" vendor="network_associates">
        <vers num="4.5"/>
      </prod>
      <prod name="virusscan" vendor="network_associates">
        <vers num="4.5" edition=":windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0651" seq="2000-0651" published="2000-07-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1440" adv="1" patch="1">1440</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=06256915.00591E18.00@uprrsmtp2.notes.up.com">20000707 Novell Border Manger - Anyone can pose as an authenticated user</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5186">novell-bordermanager-verification(5186)</ref>
    </refs>
    <vuln_soft>
      <prod name="bordermanager" vendor="novell">
        <vers num="3.0"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0652" seq="2000-0652" published="2000-07-24" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0342.html" adv="1" patch="1">20000723 IBM WebSphere default servlet handler showcode vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1500" adv="1" patch="1">1500</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5012">websphere-showcode(5012)</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0653" seq="2000-0653" published="2000-07-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1502" adv="1" patch="1">1502</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-045">MS00-045</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.01"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0654" seq="2000-0654" published="2000-07-11" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1466" adv="1" patch="1">1466</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-041">MS00-041</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4582">mssql-dts-reveal-passwords(4582)</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0655" seq="2000-0655" published="2000-07-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc">FreeBSD-SA-00:39</ref>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-011.txt.asc">NetBSD-SA2000-011</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0456.html">20000801 MDKSA-2000:027-1 netscape update</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0116.html">20000810 Conectiva Linux Security Announcement - netscape</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-046.html">RHSA-2000:046</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1503">1503</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200007242356.DAA01274%40false.com" adv="1" patch="1">20000724 JPEG COM Marker Processing Vulnerability in Netscape Browsers</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000016.html">TLSA2000017-1</ref>
    </refs>
    <vuln_soft>
      <prod name="mozilla" vendor="mozilla">
        <vers num="m15"/>
      </prod>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
        <vers num="4.05"/>
        <vers num="4.5_beta"/>
        <vers num="4.06"/>
        <vers num="4.07"/>
        <vers num="4.08"/>
        <vers num="4.51"/>
        <vers num="4.61"/>
        <vers num="4.72"/>
        <vers num="4.73"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0656" seq="2000-0656" published="2000-07-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" adv="1" patch="1">20000724 AnalogX Proxy DoS</ref>
      <ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/proxy.htm">http://www.analogx.com/contents/download/network/proxy.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1504" adv="1" patch="1">1504</ref>
    </refs>
    <vuln_soft>
      <prod name="proxy" vendor="analogx">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0657" seq="2000-0657" published="2000-07-25" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" adv="1" patch="1">20000724 AnalogX Proxy DoS</ref>
      <ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/proxy.htm">http://www.analogx.com/contents/download/network/proxy.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1504" adv="1" patch="1">1504</ref>
    </refs>
    <vuln_soft>
      <prod name="proxy" vendor="analogx">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0658" seq="2000-0658" published="2000-07-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" adv="1" patch="1">20000724 AnalogX Proxy DoS</ref>
      <ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/proxy.htm">http://www.analogx.com/contents/download/network/proxy.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1504" adv="1" patch="1">1504</ref>
    </refs>
    <vuln_soft>
      <prod name="proxy" vendor="analogx">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0659" seq="2000-0659" published="2000-07-25" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html" adv="1" patch="1">20000724 AnalogX Proxy DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1504" adv="1" patch="1">1504</ref>
    </refs>
    <vuln_soft>
      <prod name="proxy" vendor="analogx">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0660" seq="2000-0660" published="2000-07-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0173.html" adv="1" patch="1">20000712 Infosec.20000712.worldclient.2.1</ref>
      <ref source="CONFIRM" url="http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt">http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1462" adv="1">1462</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4913">worldclient-dir-traverse(4913)</ref>
    </refs>
    <vuln_soft>
      <prod name="worldclient" vendor="alt-n">
        <vers num="2.1" edition=":standard"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0661" seq="2000-0661" published="2000-07-10" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0120.html" adv="1">20000710 Remote DoS Attack in WircSrv Irc Server v5.07s Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1448" adv="1">1448</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4914">wircsrv-character-flood-dos(4914)</ref>
    </refs>
    <vuln_soft>
      <prod name="irc_server" vendor="wircsrv">
        <vers num="5.0.7s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0662" seq="2000-0662" published="2000-07-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1474">1474</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396EF9D5.62EEC625@nat.bg" adv="1">20000714 IE 5.5 and 5.01 vulnerability - reading at least local and from any host text and parsed html files</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5107">ie-dhtmled-file-read(5107)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0663" seq="2000-0663" published="2000-07-25" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=269049">Q269049</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1507" adv="1" patch="1">1507</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-052">MS00-052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5040">explorer-relative-path-name(5040)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0664" seq="2000-0664" published="2000-07-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0374.html" adv="1" patch="1">20000726 AnalogX "SimpleServer:WWW" dot dot bug</ref>
      <ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1508">1508</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4999">analogx-simpleserver-directory-path(4999)</ref>
    </refs>
    <vuln_soft>
      <prod name="simpleserver_www" vendor="analogx">
        <vers num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0665" seq="2000-0665" published="2000-07-17" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0031.html" adv="1" patch="1">20000717 DoS in Gamsoft TelSrv telnet server for MS Windows 95/98/NT/2k.</ref>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0056.html">20000729 TelSrv Reveals Usernames &amp; Passwords After DoS Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1478" adv="1">1478</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4945">gamsoft-telsrv-dos(4945)</ref>
    </refs>
    <vuln_soft>
      <prod name="telsrv" vendor="gamsoft">
        <vers num="1.4"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0666" seq="2000-0666" published="2000-07-16" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0206.html" adv="1" patch="1">20000716 Lots and lots of fun with rpc.statd</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0230.html">20000717 CONECTIVA LINUX SECURITY ANNOUNCEMENT - nfs-utils</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0236.html">20000718 Trustix Security Advisory - nfs-utils</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0260.html">20000718 [Security Announce] MDKSA-2000:021 nfs-utils update</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-025.0.txt">CSSA-2000-025.0</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-17.html">CA-2000-17</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-043.html">RHSA-2000:043</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1480" adv="1" patch="1">1480</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4939">linux-rpcstatd-format-overwrite(4939)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" edition=":alpha"/>
        <vers num="2.2" edition=":powerpc"/>
        <vers num="2.2" edition=":sparc"/>
        <vers num="2.3" edition=":alpha"/>
        <vers num="2.3" edition=":powerpc"/>
        <vers num="2.3" edition=":sparc"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3" edition=":ppc"/>
        <vers num="6.3" edition="alpha"/>
        <vers num="6.4" edition=":ppc"/>
        <vers num="6.4" edition="alpha"/>
        <vers num="7.0"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0667" seq="2000-0667" published="2000-07-27" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0273.html" adv="1" patch="1">CSSA-2000-024.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1512" adv="1" patch="1">1512</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0668" seq="2000-0668" published="2000-07-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0398.html">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - PAM</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0455.html">20000801 MDKSA-2000:029 pam update</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-044.html">RHSA-2000:044</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1513" adv="1" patch="1">1513</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5001">linux-pam-console(5001)</ref>
    </refs>
    <vuln_soft>
      <prod name="pam_console" vendor="michael_k._johnson">
        <vers num="0.66"/>
        <vers num="0.72_unpatched"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0669" seq="2000-0669" published="2000-07-11" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1467" adv="1">1467</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000501bfeab5$9330c3d0$d801a8c0@dimuthu.baysidegrp.com.au" adv="1">20000711 Remote Denial Of Service -- NetWare 5.0 with SP 5</ref>
    </refs>
    <vuln_soft>
      <prod name="netware" vendor="novell">
        <vers num="5.0" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0670" seq="2000-0670" published="2000-07-12" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:37.cvsweb.asc">FreeBSD-SA-00:37</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0178.html">20000712 cvsweb: remote shell for cvs committers</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0196.html" adv="1" patch="1">20000714 MDKSA-2000:019 cvsweb update</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1469">1469</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000015.html">TLSA2000016-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4925">cvsweb-shell-access(4925)</ref>
    </refs>
    <vuln_soft>
      <prod name="cvsweb" vendor="cvsweb_developer">
        <vers num="1.80"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0671" seq="2000-0671" published="2000-07-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0307.html">20000721 Roxen Web Server Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0321.html" adv="1" patch="1">20000721 Roxen security alert: Problems with URLs containing null characters.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1510">1510</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4965">roxen-null-char-url(4965)</ref>
    </refs>
    <vuln_soft>
      <prod name="webserver" vendor="roxen">
        <vers num="2.0.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0672" seq="2000-0672" published="2000-07-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0309.html" adv="1" patch="1">20000721 Jakarta-tomcat.../admin</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1548">1548</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5160">jakarta-tomcat-admin(5160)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="3.1"/>
      </prod>
      <prod name="tomcat" vendor="apache">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0673" seq="2000-0673" published="2000-07-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/044.asp">20000727 Windows NetBIOS Name Conflicts</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1514" adv="1" patch="1">1514</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1515">1515</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-047">MS00-047</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5035">netbios-name-server-spoofing(5035)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="terminal_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0674" seq="2000-0674" published="2000-07-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0177.html" adv="1">20000712 ftp.pl vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1471" adv="1" patch="1">1471</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5187">virtualvision-ftp-browser(5187)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_browser" vendor="virtual_vision">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0675" seq="2000-0675" published="2000-07-13" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1477" adv="1" patch="1">1477</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00af01bfece2$a52cbd80$367e1ec4@kungphusion" adv="1">20000713 The MDMA Crew's GateKeeper Exploit</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4948">gatekeeper-long-string-bo(4948)</ref>
    </refs>
    <vuln_soft>
      <prod name="gatekeeper" vendor="infopulse">
        <vers num="3.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0676" seq="2000-0676" published="2000-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc">FreeBSD-SA-00:39</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0019.html">20000804 Dangerous Java/Netscape Security Hole</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0115.html">20000810 MDKSA-2000:033 Netscape Java vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0236.html">20000818 Conectiva Linux Security Announcement - netscape</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0265.html">20000821 MDKSA-2000:036 - netscape update</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-027.1.txt">CSSA-2000-027.1</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-15.html" adv="1" patch="1">CA-2000-15</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-054.html">RHSA-2000:054</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1546" adv="1" patch="1">1546</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
        <vers num="4.04"/>
        <vers num="4.05"/>
        <vers num="4.5_beta"/>
        <vers num="4.06"/>
        <vers num="4.07"/>
        <vers num="4.08"/>
        <vers num="4.51"/>
        <vers num="4.61"/>
        <vers num="4.72"/>
        <vers num="4.73"/>
        <vers num="4.74"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0677" seq="2000-0677" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise60.php" adv="1">20000907 Buffer Overflow in IBM Net.Data db2www CGI program.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4976">ibm-netdata-db2www-bo(4976)</ref>
    </refs>
    <vuln_soft>
      <prod name="net.data" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0678" seq="2000-0678" published="2000-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-18.html" adv="1">CA-2000-18</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1606" adv="1" patch="1">1606</ref>
    </refs>
    <vuln_soft>
      <prod name="pgp" vendor="pgp">
        <vers num="5.5.3i"/>
        <vers num="6.5.1i"/>
        <vers num="6.5.3i"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0679" seq="2000-0679" published="2000-10-20" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1523" adv="1">1523</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org" adv="1">20000728 cvs security problem</ref>
    </refs>
    <vuln_soft>
      <prod name="cvs" vendor="cvs">
        <vers num="1.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0680" seq="2000-0680" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1524" adv="1" patch="1">1524</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org" adv="1">20000728 cvs security problem</ref>
    </refs>
    <vuln_soft>
      <prod name="cvs" vendor="cvs">
        <vers num="1.10.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0681" seq="2000-0681" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0186.html" adv="1" patch="1">20000815 BEA Weblogic server proxy library vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1570" adv="1" patch="1">1570</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="4.5.2" prev="1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0682" seq="2000-0682" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html" adv="1" patch="1">20000728 BEA's WebLogic force handlers show code vulnerability</ref>
      <ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1518" adv="1" patch="1">1518</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="5.1" edition=":enterprise"/>
        <vers num="5.1" edition=":express"/>
        <vers num="5.1" edition="sp1:express"/>
        <vers num="5.1" edition="sp10:express"/>
        <vers num="5.1" edition="sp11:express"/>
        <vers num="5.1" edition="sp12:express"/>
        <vers num="5.1" edition="sp2:express"/>
        <vers num="5.1" edition="sp3:express"/>
        <vers num="5.1" edition="sp4:express"/>
        <vers num="5.1" edition="sp5:express"/>
        <vers num="5.1" edition="sp6:express"/>
        <vers num="5.1" edition="sp7:express"/>
        <vers num="5.1" edition="sp8:express"/>
        <vers num="5.1" edition="sp9:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0683" seq="2000-0683" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html" adv="1" patch="1">20000728 BEA's WebLogic force handlers show code vulnerability</ref>
      <ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000728.html">http://developer.bea.com/alerts/security_000728.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1517" adv="1" patch="1">1517</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="5.1" edition=":enterprise"/>
        <vers num="5.1" edition=":express"/>
        <vers num="5.1" edition="sp1:express"/>
        <vers num="5.1" edition="sp10:express"/>
        <vers num="5.1" edition="sp11:express"/>
        <vers num="5.1" edition="sp12:express"/>
        <vers num="5.1" edition="sp2:express"/>
        <vers num="5.1" edition="sp3:express"/>
        <vers num="5.1" edition="sp4:express"/>
        <vers num="5.1" edition="sp5:express"/>
        <vers num="5.1" edition="sp6:express"/>
        <vers num="5.1" edition="sp7:express"/>
        <vers num="5.1" edition="sp8:express"/>
        <vers num="5.1" edition="sp9:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0684" seq="2000-0684" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html" adv="1" patch="1">20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution</ref>
      <ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1525" adv="1" patch="1">1525</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="3.1.8"/>
        <vers num="4.0.4"/>
        <vers num="4.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0685" seq="2000-0685" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html" adv="1" patch="1">20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution</ref>
      <ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1525" adv="1" patch="1">1525</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="3.1.8"/>
        <vers num="4.0.4"/>
        <vers num="4.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0686" seq="2000-0686" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html" adv="1">20000823 Auction WeaverT LITE 1.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1630" adv="1">1630</ref>
    </refs>
    <vuln_soft>
      <prod name="auction_weaver" vendor="cgi_script_center">
        <vers num="1.02" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0687" seq="2000-0687" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html" adv="1">20000823 Auction WeaverT LITE 1.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1630" adv="1">1630</ref>
    </refs>
    <vuln_soft>
      <prod name="auction_weaver" vendor="cgi_script_center">
        <vers num="1.02" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0688" seq="2000-0688" published="2000-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0292.html" adv="1">20000823 Subscribe Me Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96722957421029&amp;w=2">20000823 Re: Subscribe Me CGI Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.cgiscriptcenter.com/subscribe/">http://www.cgiscriptcenter.com/subscribe/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1607" adv="1" patch="1">1607</ref>
    </refs>
    <vuln_soft>
      <prod name="subscribe_me_lite" vendor="cgi_script_center">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0689" seq="2000-0689" published="2000-10-20" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html" adv="1">20000823 Account Manager CGI Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.cgiscriptcenter.com/acctlite/">http://www.cgiscriptcenter.com/acctlite/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1604" adv="1" patch="1">1604</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5125">account-manager-overwrite-password(5125)</ref>
    </refs>
    <vuln_soft>
      <prod name="account_manager" vendor="cgi_script_center">
        <vers num="lite_1.0"/>
        <vers num="pro_1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0690" seq="2000-0690" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0370.html" adv="1">20000830 More problems with Auction Weaver &amp; CGI Script Center.</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0452.html" adv="1">20000830 More problems with Auction Weaver &amp; CGI Script Center.</ref>
    </refs>
    <vuln_soft>
      <prod name="auction_weaver" vendor="cgi_script_center">
        <vers num="1.0"/>
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0691" seq="2000-0691" published="2000-10-20" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0329.html" adv="1">20000826 Advisory: mgetty local compromise</ref>
      <ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html">http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-029.0.txt" adv="1" patch="1">CSSA-2000-029.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1612" adv="1" patch="1">1612</ref>
    </refs>
    <vuln_soft>
      <prod name="mgetty" vendor="gert_doering">
        <vers num="1.1.19"/>
        <vers num="1.1.20"/>
        <vers num="1.1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0692" seq="2000-0692" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0267.html" adv="1" patch="1">20000822 DOS on RealSecure 3.2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1597" adv="1">1597</ref>
    </refs>
    <vuln_soft>
      <prod name="realsecure" vendor="iss">
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0693" seq="2000-0693" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html" adv="1">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1563" adv="1" patch="1">1563</ref>
    </refs>
    <vuln_soft>
      <prod name="raptor_gfx_pgx32" vendor="tech-source">
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0694" seq="2000-0694" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html" adv="1">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
    </refs>
    <vuln_soft>
      <prod name="raptor_gfx_pgx32" vendor="tech-source">
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0695" seq="2000-0695" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html" adv="1">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
    </refs>
    <vuln_soft>
      <prod name="raptor_gfx_pgx32" vendor="tech-source">
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0696" seq="2000-0696" published="2000-10-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://archives.neohapsis.com/archives/sun/2000-q3/0001.html" adv="1" patch="1">00196</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Aug/0105.html">20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server</ref>
      <ref source="MISC" url="http://www.s21sec.com/en/avisos/s21sec-004-en.txt">http://www.s21sec.com/en/avisos/s21sec-004-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1554" adv="1" patch="1">1554</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5069">solaris-answerbook2-admin-interface(5069)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris_answerbook2" vendor="sun">
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0697" seq="2000-0697" published="2000-10-20" modified="2008-09-24" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://archives.neohapsis.com/archives/sun/2000-q3/0001.html" adv="1" patch="1">00196</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Aug/0105.html">20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5058.php">solaris-answerbook2-remote-execution(5058)</ref>
      <ref source="MISC" url="http://www.s21sec.com/en/avisos/s21sec-004-en.txt">http://www.s21sec.com/en/avisos/s21sec-004-en.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1556" adv="1" patch="1">1556</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris_answerbook2" vendor="sun">
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0698" seq="2000-0698" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/77361" adv="1">20000819 RH 6.1 / 6.2 minicom vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1599" adv="1">1599</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5151">minicom-capture-groupown(5151)</ref>
    </refs>
    <vuln_soft>
      <prod name="minicom" vendor="minicom">
        <vers num="1.82.0"/>
        <vers num="1.82.1"/>
        <vers num="1.83.0"/>
        <vers num="1.83.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0699" seq="2000-0699" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0028.html" adv="1">20000806 HPUX FTPd vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1560" adv="1">1560</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0700" seq="2000-0700" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/gsraclbypassdos-pub.shtml" adv="1" patch="1">20000803 Possible Access Control Bypass and Denial of Service in Gigabit Switch Routers Using Gigabit Ethernet or Fast Ethernet Cards</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1541" adv="1" patch="1">1541</ref>
    </refs>
    <vuln_soft>
      <prod name="gigabit_switch_router_12008" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="gigabit_switch_router_12012" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="gigabit_switch_router_12016" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="11.2"/>
        <vers num="11.2(8)"/>
        <vers num="11.2(10)"/>
        <vers num="11.2p"/>
        <vers num="11.3"/>
        <vers num="11.3(1)"/>
        <vers num="12.0"/>
        <vers num="12.0(1)"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(3)"/>
        <vers num="12.0(4)"/>
        <vers num="12.0(5)"/>
        <vers num="12.0(6)"/>
        <vers num="12.0(7)t"/>
        <vers num="12.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0701" seq="2000-0701" published="2000-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0474.html" adv="1" patch="1">20000802 CONECTIVA LINUX SECURITY ANNOUNCEMENT - mailman</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0479.html" adv="1">20000802 MDKSA-2000:030 - Linux-Mandrake not affected by mailman problem</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-030.html">RHSA-2000:030</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/73220" adv="1" patch="1">20000801 Advisory: mailman local compromise</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1539" adv="1" patch="1">1539</ref>
      <ref source="CONFIRM" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000802105050.A11733@rak.isternet.sk">http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000802105050.A11733@rak.isternet.sk</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="2.0" edition="beta3"/>
        <vers num="2.0" edition="beta4"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0702" seq="2000-0702" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0261.html">20000821 [HackersLab bugpaper] HP-UX net.init rc script</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1602" adv="1" patch="1">1602</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5131">hp-netinit-symlink(5131)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0703" seq="2000-0703" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">suidperl (aka sperl) does not properly cleanse the escape sequence "~!" before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the "interactive" environmental variable and calling suidperl with a filename that contains the escape sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0022.html" adv="1">20000805 sperl 5.00503 (and newer ;) exploit</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0086.html">20000808 MDKSA-2000:031 perl update</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0113.html">20000810 Conectiva Linux security announcemente - PERL</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0153.html">20000814 Trustix Security Advisory - perl and mailx</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-026.0.txt" adv="1" patch="1">CSSA-2000-026.0</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_59.html">20000810 Security Hole in perl, all versions</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-048.html">RHSA-2000:048</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1547" adv="1" patch="1">1547</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000017.html">TLSA2000018-1</ref>
    </refs>
    <vuln_soft>
      <prod name="perl" vendor="larry_wall">
        <vers num="5.4.5"/>
        <vers num="5.5"/>
        <vers num="5.5.3"/>
        <vers num="5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0704" seq="2000-0704" published="2000-10-20" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://sgigate.sgi.com/security/20000803-01-A">20000803-01-A</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1603" adv="1">1603</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5163">irix-worldview-wnn-bo(5163)</ref>
    </refs>
    <vuln_soft>
      <prod name="freewnn" vendor="freewnn">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.1.1_axxx"/>
      </prod>
      <prod name="worldview" vendor="omron">
        <vers num="6.5"/>
      </prod>
      <prod name="wnn4" vendor="wnn">
        <vers num="4.2.2tl"/>
        <vers num="4.2.5tl"/>
        <vers num="4.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0705" seq="2000-0705" published="2000-10-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0459.html">20000802 [ Hackerslab bug_paper ] ntop web mode vulnerabliity</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-049.html">RHSA-2000:049</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1550" adv="1" patch="1">1550</ref>
    </refs>
    <vuln_soft>
      <prod name="ntop" vendor="luca_deri">
        <vers num="1.2a7_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0706" seq="2000-0706" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:36.ntop.asc">FreeBSD-SA-00:36</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000830" adv="1">20000830 ntop: Still remotely exploitable using buffer overflows</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1576" adv="1">1576</ref>
    </refs>
    <vuln_soft>
      <prod name="ntop" vendor="luca_deri">
        <vers num="1.2a7_9"/>
        <vers num="1.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0707" seq="2000-0707" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0015.html" adv="1" patch="1">20000804 PCCS MySQL DB Admin Tool v1.2.3- Advisory</ref>
      <ref source="CONFIRM" url="http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&amp;key=965951324">http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&amp;key=965951324</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1557" adv="1" patch="1">1557</ref>
    </refs>
    <vuln_soft>
      <prod name="mysqldatabase_admin_tool" vendor="pccs-linux">
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0708" seq="2000-0708" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=NTBUGTRAQ&amp;P=R4247" adv="1">20000824 Remote DoS Attack in Pragma TelnetServer 2000 (Remote Execute Daemon) Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.pragmasys.com/TelnetServer/">http://www.pragmasys.com/TelnetServer/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1605" adv="1">1605</ref>
    </refs>
    <vuln_soft>
      <prod name="telnetserver" vendor="pragma_systems">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0709" seq="2000-0709" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html" adv="1" patch="1">20000823 Xato Advisory: FrontPage DOS Device DoS</ref>
      <ref source="CONFIRM" url="http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp">http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1608" adv="1" patch="1">1608</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0710" seq="2000-0710" published="2000-10-20" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html" adv="1" patch="1">20000823 Xato Advisory: FrontPage DOS Device DoS</ref>
      <ref source="CONFIRM" url="http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp">http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1608" adv="1" patch="1">1608</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0711" seq="2000-0711" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-15.html" adv="1" patch="1">CA-2000-15</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1545" adv="1" patch="1">1545</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000805020429.11774.qmail@securityfocus.com" adv="1">20000805 Dangerous Java/Netscape Security Hole</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3999922128E.EE84TAKAGI@java-house.etl.go.jp" adv="1">20000816 JDK 1.1.x Listening Socket Vulnerability (was Re: BrownOrifice can break firewalls!)</ref>
    </refs>
    <vuln_soft>
      <prod name="virtual_machine" vendor="microsoft">
        <vers num="2000"/>
        <vers num="3100"/>
        <vers num="3200"/>
        <vers num="3300"/>
      </prod>
      <prod name="communicator" vendor="netscape">
        <vers num="4.0"/>
        <vers num="4.04"/>
        <vers num="4.05"/>
        <vers num="4.06"/>
        <vers num="4.07"/>
        <vers num="4.08"/>
        <vers num="4.51"/>
        <vers num="4.61"/>
        <vers num="4.72"/>
        <vers num="4.73"/>
        <vers num="4.74"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0712" seq="2000-0712" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0486.html" adv="1">2000803 LIDS severe bug</ref>
      <ref source="MISC" url="http://www.egroups.com/message/lids/1038">http://www.egroups.com/message/lids/1038</ref>
      <ref source="CONFIRM" url="http://www.lids.org/changelog.html">http://www.lids.org/changelog.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1549" adv="1" patch="1">1549</ref>
    </refs>
    <vuln_soft>
      <prod name="lids" vendor="lids">
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0713" seq="2000-0713" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0382.html" adv="1" patch="1">20000726 [SPSadvisory#39]Adobe Acrobat Series PDF File Buffer Overflow</ref>
      <ref source="CONFIRM" url="http://www.adobe.com/misc/pdfsecurity.html">http://www.adobe.com/misc/pdfsecurity.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1509" adv="1" patch="1">1509</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat" vendor="adobe">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.0.5"/>
      </prod>
      <prod name="acrobat_business_tools" vendor="adobe">
        <vers num="4.0"/>
        <vers num="4.05"/>
      </prod>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0714" seq="2000-0714" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-047.html">RHSA-2000:047</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1551" adv="1" patch="1">1551</ref>
    </refs>
    <vuln_soft>
      <prod name="scheme" vendor="university_of_massachusetts">
        <vers num="3.2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0715" seq="2000-0715" published="2000-10-20" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Aug/0082.html">20000805 Diskcheck 3.1.1 Symlink Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Aug/0096.html">20000807 Re: Diskcheck 3.1.1 Symlink Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Jun/0298.html">20000622 Re: rh 6.2 - gid compromises, etc [+ MORE!!!]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1552" adv="1" patch="1">1552</ref>
    </refs>
    <vuln_soft>
      <prod name="diskcheck" vendor="kirk_bauer">
        <vers num="3.1.1"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0716" seq="2000-0716" published="2000-10-20" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=459" adv="1" patch="1">20000809 Session hijacking in Alt-N's MDaemon 2.8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1553" adv="1" patch="1">1553</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5070">mdaemon-session-id-hijack(5070)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0717" seq="2000-0717" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1619" adv="1">1619</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=02ff01c0124c$e9387660$0201a8c0@aviram" adv="1" patch="1">20000830 [EXPL] GoodTech's FTP Server vulnerable to a DoS (RNTO)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5166">ftp-goodtech-rnto-dos(5166)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_server_95_98" vendor="goodtech">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
      </prod>
      <prod name="ftp_server_nt_2000" vendor="goodtech">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0718" seq="2000-0718" published="2000-10-20" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0146.html" adv="1" patch="1">20000812 MDKSA-2000:034 MandrakeUpdate update</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1567" adv="1" patch="1">1567</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0719" seq="2000-0719" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0126.html" adv="1" patch="1">20000810 VariCAD 7.0 premission vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="varicad" vendor="varicad">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0720" seq="2000-0720" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1621" adv="1">1621</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003301c0123b$18f8c1a0$953b29d4@e8s9s4" adv="1">20000829 News Publisher CGI Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5169">news-publisher-add-author(5169)</ref>
    </refs>
    <vuln_soft>
      <prod name="gwscripts_news_publisher" vendor="gwscripts">
        <vers num="1.05"/>
        <vers num="1.05a"/>
        <vers num="1.05b"/>
        <vers num="1.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0721" seq="2000-0721" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0114.html" adv="1" patch="1">20000810 FlagShip v4.48.7449 premission vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1586" adv="1">1586</ref>
    </refs>
    <vuln_soft>
      <prod name="flagship" vendor="multisoft">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0722" seq="2000-0722" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0240.html" adv="1">20000820 Helix Code Security Advisory - Helix GNOME Update</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html" adv="1" patch="1">20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1593" adv="1" patch="1">1593</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13QAYl-0007il-00@the-village.bc.nu">20000819 Multiple Local Vulnerabilities in Helix Gnome Installer</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome_updater" vendor="helix_code">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0723" seq="2000-0723" published="2000-10-20" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html" adv="1" patch="1">20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1596" adv="1" patch="1">1596</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13QAYl-0007il-00@the-village.bc.nu">20000819 Multiple Local Vulnerabilities in Helix Gnome Installer</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome_installer" vendor="helix_code">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0724" seq="2000-0724" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0351.html" adv="1">20000829 More Helix Code installation problems (go-gnome)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0356.html" adv="1" patch="1">20000829 Helix Code Security Advisory - go-gnome pre-installer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1622" adv="1" patch="1">1622</ref>
    </refs>
    <vuln_soft>
      <prod name="go-gnome_pre-installer" vendor="helix_code">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0725" seq="2000-0725" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html" adv="1" patch="1">20000816 MDKSA-2000:035 Zope update</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0259.html" patch="1">20000821 Conectiva Linux Security Announcement - Zope</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000821" adv="1">20000821 zope: unauthorized escalation of privilege (update)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-052.html">RHSA-2000:052</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1577" adv="1" patch="1">1577</ref>
      <ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert">http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="1.10.3"/>
        <vers num="2.1.1"/>
        <vers num="2.1.7"/>
        <vers num="2.2_beta1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0726" seq="2000-0726" published="2000-10-20" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1623" adv="1">1623</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000829194618.H7744@thathost.com" adv="1">20000829 Stalker's CGImail Gives Read Access to All Server Files</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5165">mailers-cgimail-spoof(5165)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailers" vendor="stalkerlab">
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0727" seq="2000-0727" published="2000-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96766355023239&amp;w=2">20000829 MDKSA-2000:041 - xpdf update</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96886599829687&amp;w=2">20000913 Conectiva Linux Security Announcement - xpdf</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt" adv="1" patch="1">CSSA-2000-031.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000910a" adv="1" patch="1">20000910 xpdf: local exploit</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-060.html">RHSA-2000:060</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1624" adv="1" patch="1">1624</ref>
    </refs>
    <vuln_soft>
      <prod name="xpdf" vendor="xpdf">
        <vers num="0.90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0728" seq="2000-0728" published="2000-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96766355023239&amp;w=2">20000829 MDKSA-2000:041 - xpdf update</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96886599829687&amp;w=2">20000913 Conectiva Linux Security Announcement - xpdf</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt">CSSA-2000-031.0</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-060.html">RHSA-2000:060</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1624" adv="1" patch="1">1624</ref>
    </refs>
    <vuln_soft>
      <prod name="xpdf" vendor="xpdf">
        <vers num="0.90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0729" seq="2000-0729" published="2000-10-20" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0337.html" adv="1" patch="1">FreeBSD-SA-00:41</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1625" adv="1" patch="1">1625</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5967">freebsd-elf-dos(5967)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="4.1"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0730" seq="2000-0730" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html" adv="1" patch="1">HPSBUX0008-118</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1580" adv="1" patch="1">1580</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0731" seq="2000-0731" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html" adv="1" patch="1">20000825 DST2K0023: Directory Traversal Possible &amp; Denial of Service in Wo rm HTTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1626" adv="1">1626</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5148">wormhttp-dir-traverse(5148)</ref>
    </refs>
    <vuln_soft>
      <prod name="worm_webserver" vendor="jeremy_arnold">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0732" seq="2000-0732" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Worm HTTP server allows remote attackers to cause a denial of service via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html" adv="1" patch="1">20000825 DST2K0023: Directory Traversal Possible &amp; Denial of Service in Wo rm HTTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1626" adv="1">1626</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5149">wormhttp-filename-dos(5149)</ref>
    </refs>
    <vuln_soft>
      <prod name="worm_webserver" vendor="jeremy_arnold">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0733" seq="2000-0733" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://sgigate.sgi.com/security/20000801-02-P">20000801-02-P</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.html" adv="1" patch="1">20000814 [LSD] IRIX telnetd remote vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1572" adv="1">1572</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="5.2"/>
        <vers num="5.3" edition=":xfs"/>
        <vers num="6.0"/>
        <vers num="6.0.1" edition=":xfs"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0734" seq="2000-0734" published="2000-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96774637326591&amp;w=2">20000831 Remote DoS Attack in Eeye Iris 1.01 and SpyNet CaptureNet v3.12</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1627" adv="1" patch="1">1627</ref>
    </refs>
    <vuln_soft>
      <prod name="iris" vendor="eeye_digital_security">
        <vers num="1.0.1"/>
      </prod>
      <prod name="capturenet" vendor="spynet">
        <vers num="3.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0735" seq="2000-0735" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html" adv="1" patch="1">20000818 Becky! Internet Mail Buffer overflow</ref>
      <ref source="CONFIRM" url="http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt">http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1588" adv="1">1588</ref>
    </refs>
    <vuln_soft>
      <prod name="becky_internet_mail" vendor="rimarts_inc.">
        <vers num="1.26.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0736" seq="2000-0736" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html" adv="1" patch="1">20000818 Becky! Internet Mail Buffer overflow</ref>
      <ref source="CONFIRM" url="http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt">http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1588" adv="1">1588</ref>
    </refs>
    <vuln_soft>
      <prod name="becky_internet_mail" vendor="rimarts_inc.">
        <vers num="1.26.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0737" seq="2000-0737" published="2000-10-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1535" adv="1" patch="1">1535</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-053">MS00-053</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0738" seq="2000-0738" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0101.html" adv="1" patch="1">20000818 WebShield SMTP infinite loop DoS Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1589" adv="1" patch="1">1589</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5100">webshield-smtp-dos(5100)</ref>
    </refs>
    <vuln_soft>
      <prod name="webshield_smtp" vendor="network_associates">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0739" seq="2000-0739" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html" adv="1">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
      <ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1537" adv="1" patch="1">1537</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5066">nettools-pki-dir-traverse(5066)</ref>
    </refs>
    <vuln_soft>
      <prod name="net_tools_pki_server" vendor="network_associates">
        <vers num="1.0"/>
        <vers num="1.0hotfix1"/>
        <vers num="1.0hotfix2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0740" seq="2000-0740" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html" adv="1">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
      <ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1536" adv="1" patch="1">1536</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5026">nai-nettools-strong-bo(5026)</ref>
    </refs>
    <vuln_soft>
      <prod name="net_tools_pki_server" vendor="network_associates">
        <vers num="1.0"/>
        <vers num="1.0hotfix1"/>
        <vers num="1.0hotfix2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0741" seq="2000-0741" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html" adv="1">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
      <ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1538" adv="1" patch="1">1538</ref>
    </refs>
    <vuln_soft>
      <prod name="net_tools_pki_server" vendor="network_associates">
        <vers num="1.0"/>
        <vers num="1.0hotfix1"/>
        <vers num="1.0hotfix2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0742" seq="2000-0742" published="2000-10-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1544" adv="1" patch="1">1544</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;mid=63120" adv="1">20000602 ipx storm</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-054">MS00-054</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5079">win-ipx-ping-packet(5079)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0743" seq="2000-0743" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0112.html" adv="1" patch="1">20000810 Remote vulnerability in Gopherd 2.x</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1569" adv="1" patch="1">1569</ref>
    </refs>
    <vuln_soft>
      <prod name="gopherd" vendor="university_of_minnesota">
        <vers num="2.3"/>
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0744" seq="2000-0744" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-2000-0743.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="gopherd" vendor="university_of_minnesota">
        <vers num="2.3"/>
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0745" seq="2000-0745" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0243.html" adv="1" patch="1">20000821 Vuln. in all sites using PHP-Nuke, versions less than 3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1592" adv="1" patch="1">1592</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="1.0"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0746" seq="2000-0746" published="2000-10-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks.  They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.  The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1594" adv="1" patch="1">1594</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1595" adv="1" patch="1">1595</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39A12BD6.E811BF4F@nat.bg">20000821 IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-060">MS00-060</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0747" seq="2000-0747" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0379.html" adv="1" patch="1">20000726 CONECTIVA LINUX SECURITY ANNOUNCEMENT - OPENLDAP</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5036">openldap-logrotate-script-dos(5036)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="conectiva">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0748" seq="2000-0748" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0375.html" adv="1" patch="1">20000726 Group-writable executable in OpenLDAP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1511" adv="1" patch="1">1511</ref>
    </refs>
    <vuln_soft>
      <prod name="openldap" vendor="openldap">
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0749" seq="2000-0749" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0338.html" adv="1" patch="1">FreeBSD-SA-00:42</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1628" adv="1" patch="1">1628</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5968">freebsd-linux-module-bo(5968)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0750" seq="2000-0750" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html" adv="1">20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html" adv="1" patch="1">FreeBSD-SA-00:40</ref>
      <ref source="MISC" url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h">http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata.html#mopd">20000705 Mopd contained a buffer overflow.</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-050.html">RHSA-2000:050</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1558" adv="1" patch="1">1558</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0751" seq="2000-0751" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html" adv="1">20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html" adv="1" patch="1">FreeBSD-SA-00:40</ref>
      <ref source="MISC" url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h">http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata.html#mopd">20000705 Mopd contained a buffer overflow.</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-050.html">RHSA-2000:050</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1559" adv="1" patch="1">1559</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0752" seq="2000-0752" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0339.html" adv="1" patch="1">FreeBSD-SA-00:43</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1629" adv="1" patch="1">1629</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="4.1"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0753" seq="2000-0753" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201422">20010802 Outlook 2000 Rich Text information disclosure</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/78240">20000824 Outlook winmail.dat</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1631" adv="1" patch="1">1631</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5508">outlook-reveal-path(5508)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="97"/>
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0754" seq="2000-0754" published="2000-10-20" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html" adv="1" patch="1">HPSBUX0008-119</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1581" adv="1">1581</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0755" seq="2000-0755" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html" adv="1" patch="1">HPSBUX0008-118</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1581" adv="1">1581</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0756" seq="2000-0756" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1633" adv="1">1633</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Springmail.105.967737080.0.16997300@www.springmail.com">20000831 vCard DoS on Outlook 2000</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0757" seq="2000-0757" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0074.html" adv="1">20000808 Exploit for Totalbill...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1555" adv="1">1555</ref>
    </refs>
    <vuln_soft>
      <prod name="totalbill" vendor="aptis_software">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0758" seq="2000-0758" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0149.html" adv="1" patch="1">20000811 Lyris List Manager Administration Hole</ref>
      <ref source="CONFIRM" url="http://www.lyris.com/lm/lm_updates.html">http://www.lyris.com/lm/lm_updates.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1584" adv="1" patch="1">1584</ref>
    </refs>
    <vuln_soft>
      <prod name="list_manager" vendor="lyris">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0759" seq="2000-0759" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/4967.php">tomcat-error-path-reveal(4967)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1531" adv="1">1531</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719184401.17782A-100000@grex.cyberspace.org" adv="1">20000719 [LoWNOISE] Tomcat 3.1 Path Revealing Problem.</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0760" seq="2000-0760" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1532" adv="1">1532</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719235404.24004A-100000@grex.cyberspace.org" adv="1">20000719 [LoWNOISE] Snoop Servlet (Tomcat 3.1 and 3.0)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0761" seq="2000-0761" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README">ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0166.html" adv="1" patch="1">20000815 OS/2 Warp 4.5 FTP Server DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1582" adv="1" patch="1">1582</ref>
    </refs>
    <vuln_soft>
      <prod name="os2_ftp_server" vendor="ibm">
        <vers num="4.0"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0762" seq="2000-0762" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.ca.com/techbases/eTrust/etrust_access_control-response.html">http://support.ca.com/techbases/eTrust/etrust_access_control-response.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1583" adv="1" patch="1">1583</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=004601c003a1$ba473260$ddeaa2cd@itradefair.net" adv="1" patch="1">20000811 eTrust Access Control - Root compromise for default install</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5076">etrust-access-control-default(5076)</ref>
    </refs>
    <vuln_soft>
      <prod name="etrust_access_control" vendor="ca">
        <vers num="4.1" edition="sp1"/>
        <vers num="5.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0763" seq="2000-0763" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0212.html">20000817 Conectiva Linux Security Announcement - xlockmore</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0294.html">20000823 MDKSA-2000:038 - xlockmore update</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0340.html" adv="1" patch="1">FreeBSD-SA-00:44.xlockmore</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000816" adv="1" patch="1">20000816 xlockmore: possible shadow file compromise</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1585" adv="1" patch="1">1585</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000815231724.A14694@subterrain.net" adv="1" patch="1">20000816 xlock vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="xlock" vendor="david_bagley">
        <vers num="4.16"/>
        <vers num="4.16.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0764" seq="2000-0764" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0338.html" adv="1">20000828 Intel Express Switch 500 series DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1609" adv="1">1609</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5154">intel-express-switch-dos(5154)</ref>
    </refs>
    <vuln_soft>
      <prod name="express_8100" vendor="intel">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0765" seq="2000-0765" published="2000-10-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1561" adv="1" patch="1">1561</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-056">MS00-056</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="powerpoint" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0766" seq="2000-0766" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1610" adv="1" patch="1">1610</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008270354.UAA10952@user4.hushmail.com" adv="1">20000819 D.o.S Vulnerability in vqServer</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5152">vqserver-get-dos(5152)</ref>
    </refs>
    <vuln_soft>
      <prod name="vqserver" vendor="vqsoft">
        <vers num="1.4.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0767" seq="2000-0767" published="2000-10-20" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1564" adv="1" patch="1">1564</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-055">MS00-055</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0768" seq="2000-0768" published="2000-10-20" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1564" adv="1" patch="1">1564</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-055">MS00-055</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0" edition=":windows_98"/>
        <vers num="4.0" edition=":windows_nt"/>
        <vers num="5.0" edition=":windows"/>
        <vers num="5.0" edition=":windows_2000"/>
        <vers num="5.0" edition=":windows_95"/>
        <vers num="5.0" edition=":windows_98"/>
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0769" seq="2000-0769" published="2000-10-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96715834610888&amp;w=2">20000824 WebServer Pro 2.3.7 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1611" adv="1" patch="1">1611</ref>
    </refs>
    <vuln_soft>
      <prod name="website_pro" vendor="oreilly">
        <vers num="2.3.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0770" seq="2000-0770" published="2000-10-20" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1565" adv="1" patch="1">1565</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-057">MS00-057</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0771" seq="2000-0771" published="2000-10-20" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1613" adv="1" patch="1">1613</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-062">MS00-062</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0772" seq="2000-0772" published="2000-10-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0098.html" adv="1">20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password vulnerability</ref>
      <ref source="CONFIRM" url="http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm">http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1562" adv="1" patch="1">1562</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5072">tumbleweed-mms-blank-password(5072)</ref>
    </refs>
    <vuln_soft>
      <prod name="messaging_management_system" vendor="tumbleweed">
        <vers num="4.3"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0773" seq="2000-0773" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html" adv="1">20000731 Two security flaws in Bajie Webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1522" adv="1">1522</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5021">bajie-view-arbitrary-files(5021)</ref>
    </refs>
    <vuln_soft>
      <prod name="java_http_server" vendor="bajie">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0774" seq="2000-0774" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html" adv="1">20000731 Two security flaws in Bajie Webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1521" adv="1" patch="1">1521</ref>
    </refs>
    <vuln_soft>
      <prod name="java_http_server" vendor="bajie">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0775" seq="2000-0775" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.robtex.com/viking/bugs.htm">http://www.robtex.com/viking/bugs.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1614" adv="1" patch="1">1614</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=399a01c01122$0d7f2310$0201a8c0@aviram">20000828 [NT] Viking security vulnerabilities enable remote code execution (long URL, date parsing)</ref>
    </refs>
    <vuln_soft>
      <prod name="viking_server" vendor="robtex">
        <vers num="1.0.6_build355" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0776" seq="2000-0776" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0118.html" adv="1">20000810 [DeepZone Advisory] Statistics Server 5.02x stack overflow (Win2k remote exploit)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1568" adv="1" patch="1">1568</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5113">mediahouse-stats-livestats-bo(5113)</ref>
    </refs>
    <vuln_soft>
      <prod name="statistics_server_livestats" vendor="mediahouse_software">
        <vers num="5.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0777" seq="2000-0777" published="2000-10-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1615" adv="1">1615</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-061">MS00-061</ref>
    </refs>
    <vuln_soft>
      <prod name="money" vendor="microsoft">
        <vers num="2000"/>
        <vers num="2001"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0778" seq="2000-0778" published="2000-10-20" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5212" adv="1">20000816 Translate: f</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1578" adv="1">1578</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=080D5336D882D211B56B0060080F2CD696A7C9@beta.mia.cz" adv="1" patch="1">20000815 Translate:f summary, history and thoughts</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-058">MS00-058</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A927">oval:org.mitre.oval:def:927</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0779" seq="2000-0779" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1534" adv="1" patch="1">1534</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0780" seq="2000-0780" published="2000-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96767207207553&amp;w=2">20000830 Vulnerability Report On IPSWITCH's IMail</ref>
      <ref source="CONFIRM" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1617" adv="1">1617</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0781" seq="2000-0781" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0431.html">20000728 Client Agent 6.62 for Unix Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1519" adv="1">1519</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5023">arcserveit-clientagent-temp-file(5023)</ref>
    </refs>
    <vuln_soft>
      <prod name="arcserve_backup" vendor="ca">
        <vers num="6.63_linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0782" seq="2000-0782" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://netwinsite.com/netauth/updates.htm">http://netwinsite.com/netauth/updates.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1587" adv="1" patch="1">1587</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NEBBJCLKGNOGCOIOBJNAGEHLCPAA.marc@eeye.com" adv="1" patch="1">20000817 Netauth: Web Based Email Management System</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5090">netwin-netauth-dir-traverse(5090)</ref>
    </refs>
    <vuln_soft>
      <prod name="netauth" vendor="netwin">
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0783" seq="2000-0783" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0162.html" adv="1" patch="1">20000815 Watchguard Firebox Authentication DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1573" adv="1" patch="1">1573</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5098">firebox-url-dos(5098)</ref>
    </refs>
    <vuln_soft>
      <prod name="firebox" vendor="watchguard">
        <vers num="ii"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0784" seq="2000-0784" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0216.html" adv="1" patch="1">20000816 Remote Root Compromise On All RapidStream VPN Appliances</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1574" adv="1" patch="1">1574</ref>
    </refs>
    <vuln_soft>
      <prod name="rapidstream" vendor="rapidstream">
        <vers num="2000"/>
        <vers num="4000"/>
        <vers num="6000"/>
        <vers num="8000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0785" seq="2000-0785" published="2000-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WircSrv IRC Server 5.07s allows IRC operators to read arbitrary files via the importmotd command, which sets the Message of the Day (MOTD) to the specified file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96353027909756&amp;w=2">20000713 More wIRCSrv stupidity</ref>
    </refs>
    <vuln_soft>
      <prod name="irc_server" vendor="wircsrv">
        <vers num="5.0.7s"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0786" seq="2000-0786" published="2000-10-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0389.html" adv="1">20000726 userv security boundary tool 1.0.1 (SECURITY FIX)</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=bugtraq&amp;m=96473640717095&amp;w=2">http://marc.info/?l=bugtraq&amp;m=96473640717095&amp;w=2</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000727" adv="1">20000727 userv: local exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1516" adv="1">1516</ref>
    </refs>
    <vuln_soft>
      <prod name="userv" vendor="gnu">
        <vers num="1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0787" seq="2000-0787" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0215.html" adv="1">20000817 XChat URL handler vulnerabilty</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0301.html" adv="1">20000824 MDKSA-2000:039 - xchat update</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0305.html" adv="1">20000825 Conectiva Linux Security Announcement - xchat</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-055.html">RHSA-2000:055</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1601" adv="1">1601</ref>
    </refs>
    <vuln_soft>
      <prod name="xchat" vendor="xchat">
        <vers num="1.2.1"/>
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.5.6"/>
        <vers num="1.5.xdev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0788" seq="2000-0788" published="2000-10-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1566" adv="1">1566</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398EB9CA.27E03A9C@nat.bg" adv="1">20000807 MS Word and MS Access vulnerability - executing arbitrary programs, may be exploited by IE/Outlook</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-071">MS00-071</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5322">word-mail-merge(5322)</ref>
    </refs>
    <vuln_soft>
      <prod name="access" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="word" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0789" seq="2000-0789" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0201.html" adv="1">20000816 WinU 4/5 weak password vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="winu" vendor="bardon_data_systems">
        <vers num="4.x"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0790" seq="2000-0790" published="2000-10-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1571" adv="1">1571</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3998370D.732A03F1@nat.bg" adv="1">20000828 IE 5.5/5.x for Win98 may execute arbitrary files that can be accessed thru Microsoft Networking. Also local Administrator compromise at least on default Windows 2000.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5097">ie-folder-remote-exe(5097)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0791" seq="2000-0791" published="2000-10-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0179.html" adv="1" patch="1">20000815 Trustix security advisory - apache-ssl</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1575" adv="1">1575</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0792" seq="2000-0792" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0252.html" adv="1" patch="1">20000819 Security update for Gnome-Lokkit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1590" adv="1">1590</ref>
    </refs>
    <vuln_soft>
      <prod name="gnome-lokkit" vendor="alan_cox">
        <vers num="0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0793" seq="2000-0793" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1533" adv="1">1533</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398222C5@zathras.cc.vt.edu">20000728 Norton Antivirus Protection Disabled under Novell Netware</ref>
    </refs>
    <vuln_soft>
      <prod name="client" vendor="novell">
        <vers num="3.1"/>
      </prod>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0794" seq="2000-0794" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/5063.php">irix-libgl-bo(5063)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1527" adv="1">1527</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0795" seq="2000-0795" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1529" adv="1">1529</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0796" seq="2000-0796" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1528" adv="1">1528</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5064">irix-dmplay-bo(5064)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0797" seq="2000-0797" published="2000-10-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040104-01-P.asc">20040104-01-P</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1526" adv="1">1526</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5062">irix-grosview-bo(5062)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0798" seq="2000-0798" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1540" adv="1">1540</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0799" seq="2000-0799" published="2000-10-20" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on the .ilmpAAA temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I">20001101-01-I</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1530" adv="1">1530</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl" adv="1">20000802 [LSD] some unpublished LSD exploit codes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5065">irix-inpview-symlink(5065)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0800" seq="2000-0800" published="2000-10-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_58.html">20000810 Security Hole in knfsd, all versions</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1" edition="alpha"/>
        <vers num="6.2"/>
        <vers num="6.3" edition=":ppc"/>
        <vers num="6.3" edition="alpha"/>
        <vers num="6.4" edition=":ppc"/>
        <vers num="6.4" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0801" seq="2000-0801" published="2000-10-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0388.html" adv="1">20000727 [ Hackerslab bug_paper ] HP-UX bdf -t option buffer overflow vul.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1520" adv="1">1520</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0802" seq="2000-0802" published="2000-10-20" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96430372326912&amp;w=2">20000722 More bad censorware</ref>
    </refs>
    <vuln_soft>
      <prod name="personal_privacy" vendor="pgp">
        <vers num="6.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0803" seq="2000-0803" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5280">gnu-groff-utilities(5280)</ref>
    </refs>
    <vuln_soft>
      <prod name="groff" vendor="gnu">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0804" seq="2000-0804" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5468">fw1-remote-bypass(5468)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0805" seq="2000-0805" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka "Retransmission of Encapsulated Packets."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5469">fw1-client-spoof(5469)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0806" seq="2000-0806" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka "Inter-module Communications Bypass."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5162">fw1-fwa1-auth-replay(5162)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0807" seq="2000-0807" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authentication Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication">http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5471">fw1-opsec-auth-spoof(5471)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0808" seq="2000-0808" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka "One-time (s/key) Password Authentication."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5137">fw1-localhost-auth(5137)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0809" seq="2000-0809" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Getkey in the protocol checker in the inter-module communication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5139">fw1-getkey-bo(5139)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0810" seq="2000-0810" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1782">1782</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5371">auction-weaver-delete-files(5371)</ref>
    </refs>
    <vuln_soft>
      <prod name="auction_weaver" vendor="cgi_script_center">
        <vers num="1.0"/>
        <vers num="1.01"/>
        <vers num="1.02"/>
        <vers num="1.03"/>
        <vers num="1.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0811" seq="2000-0811" published="2000-12-19" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1783">1783</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5372">auction-weaver-username-bidfile(5372)</ref>
    </refs>
    <vuln_soft>
      <prod name="auction_weaver" vendor="cgi_script_center">
        <vers num="1.0"/>
        <vers num="1.01"/>
        <vers num="1.02"/>
        <vers num="1.03"/>
        <vers num="1.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0812" seq="2000-0812" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/197&amp;type=0&amp;nav=sec.sba" adv="1" patch="1">00197</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1600">1600</ref>
      <ref source="MISC" url="http://www.securityfocus.com/templates/advisory.html?id=2542" adv="1" patch="1">http://www.securityfocus.com/templates/advisory.html?id=2542</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5135">sunjava-webadmin-bbs(5135)</ref>
    </refs>
    <vuln_soft>
      <prod name="java_system_web_server" vendor="sun">
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1_beta"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0813" seq="2000-0813" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers ("FTP Bounce") via invalid FTP commands that are processed improperly by FireWall-1, aka "FTP Connection Enforcement Bypass."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection">http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5474">fw1-ftp-redirect(5474)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0816" seq="2000-0816" published="2000-10-06" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-056.php3?dis=7.1">MDKSA-2000:056</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-080.html">RHSA-2000:080</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1785">1785</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise64.php" adv="1">20001006 Insecure call of external programs in Red Hat Linux tmpwatch</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5320">linux-tmpwatch-fuser(5320)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0817" seq="2000-0817" published="2000-12-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ISS" url="http://xforce.iss.net/alerts/index.php" adv="1">20001101 Buffer Overflow in Microsoft Windows NT 4.0 and Windows 2000 Network Monitor</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-083">MS00-083</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5399">network-monitor-bo(5399)</ref>
    </refs>
    <vuln_soft>
      <prod name="network_monitor" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0818" seq="2000-0818" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise66.php" adv="1">20001025 Vulnerability in the Oracle Listener Program</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5380">oracle-listener-connect-statements(5380)</ref>
    </refs>
    <vuln_soft>
      <prod name="listener" vendor="oracle">
        <vers num="7.3.4"/>
        <vers num="8.0.6"/>
        <vers num="8.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0824" seq="2000-0824" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html">20000902 Conectiva Linux Security Announcement - glibc</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0509.html">20000905 Conectiva Linux Security Announcement - glibc</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0525.html">20000906 [slackware-security]: glibc 2.1.3 vulnerabilities patched</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-028.0.txt">CSSA-2000-028.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000902">20000902 glibc: local root exploit</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-040.php3">MDKSA-2000:040</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-045.php3">MDKSA-2000:045</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html">20000924 glibc locale security problem</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-057.html">RHSA-2000:057</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/79537" adv="1" patch="1">20000831 glibc unsetenv bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1639">1639</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/648" adv="1" patch="1">648</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html">TLSA2000020-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5173">glibc-ld-unsetenv(5173)</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0825" seq="2000-0825" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Ipswitch Imail 6.0 allows remote attackers to cause a denial of service via a large number of connections in which a long Host: header is sent, which causes a thread to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0071.html" adv="1">20000817 Imail Web Service Remote DoS Attack v.2</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96659012127444&amp;w=2">20000817 Imail Web Service Remote DoS Attack v.2</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=96654521004571&amp;w=2">20000817 Imail Web Service Remote DoS Attack v.2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2011">2011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5475">ipswitch-imail-remote-dos(5475)</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0826" seq="2000-0826" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090800-1.txt">A090800-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1657" adv="1" patch="1">1657</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5210">documentdirect-get-bo(5210)</ref>
    </refs>
    <vuln_soft>
      <prod name="documentdirect_for_the_internet" vendor="mobius">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0827" seq="2000-0827" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090800-1.txt">A090800-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1657" adv="1" patch="1">1657</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5211">documentdirect-username-bo(5211)</ref>
    </refs>
    <vuln_soft>
      <prod name="documentdirect_for_the_internet" vendor="mobius">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0828" seq="2000-0828" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090800-1.txt">A090800-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1657" adv="1" patch="1">1657</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5212">documentdirect-user-agent-bo(5212)</ref>
    </refs>
    <vuln_soft>
      <prod name="documentdirect_for_the_internet" vendor="mobius">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0829" seq="2000-0829" published="2000-11-14" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-080.html">RHSA-2000:080</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81364">20000909 tmpwatch: local DoS : fork()bomb as root</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1664" adv="1" patch="1">1664</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5217">linux-tmpwatch-fork-dos(5217)</ref>
    </refs>
    <vuln_soft>
      <prod name="tmpwatch" vendor="redhat">
        <vers num="2.2"/>
        <vers num="2.5.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.1" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0830" seq="2000-0830" published="2000-11-14" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81852">20000913 trivial DoS in webTV</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1671" adv="1" patch="1">1671</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-074">MS00-074</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5216">webtv-udp-dos(5216)</ref>
    </refs>
    <vuln_soft>
      <prod name="webtv" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0831" seq="2000-0831" published="2000-11-14" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0109.html" adv="1" patch="1">20000912 DST2K0027: DoS in Faststream FTP++ 2.0</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp++_server" vendor="fastream">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0832" seq="2000-0832" published="2000-11-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0208.html" adv="1">20000817 Htgrep CGI Arbitrary File Viewing Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5476">htgrep-cgi-view-files(5476)</ref>
    </refs>
    <vuln_soft>
      <prod name="htgrep" vendor="oscar_nierstrasz">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0833" seq="2000-0833" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81693">2000911 WinSMTPD remote exploit/DoS problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1680" adv="1">1680</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5255">winsmtp-helo-bo(5255)</ref>
    </refs>
    <vuln_soft>
      <prod name="winsmtp" vendor="jack_de_winter">
        <vers num="1.6f"/>
        <vers num="2.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0834" seq="2000-0834" published="2000-11-14" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a091400-1.txt">A091400-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1683" adv="1" patch="1">1683</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-067">MS00-067</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5242">win2k-telnet-ntlm-authentication(5242)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0835" seq="2000-0835" published="2000-11-14" modified="2010-01-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0175.html">20000915 Sambar Server search CGI vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1684" adv="1" patch="1">1684</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="4.3"/>
        <vers num="4.4" edition="beta3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0836" seq="2000-0836" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0176.html" adv="1">20000915 [NEWS] Vulnerability in CamShot server (Authorization)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1685" adv="1">1685</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5246">camshot-password-bo(5246)</ref>
    </refs>
    <vuln_soft>
      <prod name="camshot_webcam" vendor="broadgun_software">
        <vers num="2.6trial_version"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0837" seq="2000-0837" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/73843" adv="1">20000804 FTP Serv-U 2.5e vulnerability.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1543">1543</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5029">servu-null-character-dos(5029)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_serv-u" vendor="deerfield">
        <vers num="2.5e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0838" seq="2000-0838" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0111.html" adv="1">20000914 DST2K0028: DoS in FUR HTTP Server v1.0b</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5237">fur-get-dos(5237)</ref>
    </refs>
    <vuln_soft>
      <prod name="fur_http_server" vendor="fastream">
        <vers num="1.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0839" seq="2000-0839" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WinCOM LPD 1.00.90 allows remote attackers to cause a denial of service via a large number of LPD options to the LPD port (515).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0212.html">20000919 VIGILANTE-2000013: WinCOM LPD DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1701" adv="1">1701</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5258">wincom-lpd-dos(5258)</ref>
    </refs>
    <vuln_soft>
      <prod name="wincom_lpd" vendor="ipswitch">
        <vers num="1.00.90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0840" seq="2000-0840" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html" adv="1" patch="1">20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1652" adv="1">1652</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5192">xmail-long-user-bo(5192)</ref>
    </refs>
    <vuln_soft>
      <prod name="xmail" vendor="davide_libenzi">
        <vers num="0.58"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0841" seq="2000-0841" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html" adv="1" patch="1">20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1652">1652</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5191">xmail-long-apop-bo(5191)</ref>
    </refs>
    <vuln_soft>
      <prod name="xmail" vendor="davide_libenzi">
        <vers num="0.58"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0842" seq="2000-0842" published="2000-11-14" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0086.html" adv="1">20000911 SCO scohelhttp documentation webserver exposes local files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1663" adv="1">1663</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0843" seq="2000-0843" published="2000-11-14" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0073.html">20000910 (SRADV00002) Remote root compromise through pam_smb and pam_ntdom</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0114.html">20000911 Conectiva Linux Security Announcement - pam_smb</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000911" adv="1" patch="1">20000911 libpam-smb: remote root exploit</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-047.php3">MDKSA-2000:047</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv8_draht_pam_smb_txt.html">20000913 pam_smb remotely exploitable buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1666" adv="1" patch="1">1666</ref>
    </refs>
    <vuln_soft>
      <prod name="pam_smb" vendor="dave_airlie">
        <vers num="1.1.5"/>
      </prod>
      <prod name="pam_ntdom" vendor="luke_kenneth_casson_leighton">
        <vers num="0.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0844" seq="2000-0844" published="2000-11-14" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Some functions that implement the locale subsystem on Unix do not  properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P">20000901-01-P</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html">20000902 Conectiva Linux Security Announcement - glibc</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0457.html" adv="1" patch="1">20000904 UNIX locale format string vulnerability</ref>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0427.html">IY13753</ref>
      <ref source="COMPAQ" url="http://archives.neohapsis.com/archives/tru64/2000-q4/0000.html">SSRT0689U</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-030.0.txt">CSSA-2000-030.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000902">20000902 glibc: local root exploit</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html">20000906 glibc locale security problem</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-057.html">RHSA-2000:057</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1634" adv="1" patch="1">1634</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5176">unix-locale-format-string(5176)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_ebuilder" vendor="caldera">
        <vers num="3.0"/>
      </prod>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="3.2"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="4.1.4"/>
        <vers num="4.1.5"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="6.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0845" seq="2000-0845" published="2000-11-14" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0204.html" adv="1" patch="1">20000918 [ENIGMA] Digital UNIX/Tru64 UNIX remote kdebug Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="4.0f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0846" seq="2000-0846" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0256.html" adv="1">20000821 Darxite daemon remote exploit/DoS problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1598" adv="1">1598</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5134">darxite-login-bo(5134)</ref>
    </refs>
    <vuln_soft>
      <prod name="darxite" vendor="ashley_montanaro">
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0847" seq="2000-0847" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0425.html">20000901 UW c-client library vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0437.html" adv="1">20000901 More about UW c-client library</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0108.html">FreeBSD-SA-00:47.pine</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1646" adv="1">1646</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1687">1687</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5223">c-client-dos(5223)</ref>
    </refs>
    <vuln_soft>
      <prod name="imap" vendor="university_of_washington">
        <vers num="4.7b"/>
        <vers num="4.7c"/>
      </prod>
      <prod name="pine" vendor="university_of_washington">
        <vers num="4.20"/>
        <vers num="4.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0848" seq="2000-0848" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host:  request header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0192.html" adv="1" patch="1">20000915 WebSphere application server plugin issue &amp; vendor fix</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1691" adv="1" patch="1">1691</ref>
      <ref source="MISC" url="http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security">http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5252">websphere-header-dos(5252)</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="3.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0849" seq="2000-0849" published="2000-11-14" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1655" adv="1" patch="1">1655</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-064">MS00-064</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5193">unicast-service-dos(5193)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_services" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0850" seq="2000-0850" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a091100-1.txt" adv="1">A091100-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1681" adv="1" patch="1">1681</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5230">siteminder-bypass-authentication(5230)</ref>
    </refs>
    <vuln_soft>
      <prod name="siteminder" vendor="netegrity">
        <vers num="3.6"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0851" seq="2000-0851" published="2000-11-14" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090700-1.txt">A090700-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1651" adv="1" patch="1">1651</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-065">MS00-065</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5203">w2k-still-image-service(5203)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0852" seq="2000-0852" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0110.html">FreeBSD-SA-00:49</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1686" adv="1" patch="1">1686</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5248">freebsd-eject-port(5248)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0853" seq="2000-0853" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0072.html" adv="1">20000909 YaBB 1.9.2000 Vulnerabilitie</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1668" adv="1" patch="1">1668</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5254">yabb-file-access(5254)</ref>
    </refs>
    <vuln_soft>
      <prod name="yabb" vendor="yabb">
        <vers num="2000-09-01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0854" seq="2000-0854" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.html">20000922 Eudora + riched20.dll affects WinZip v8.0 as well</ref>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.html">20000921 Mitigators for possible exploit of Eudora via Guninski #21,2000</ref>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.html" adv="1">20000918 Double clicking on MS Office documents from Windows Explorer may execute arbitrary programs in some cases</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1699" adv="1" patch="1">1699</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5263">office-dll-execution(5263)</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0855" seq="2000-0855" published="2000-11-14" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html" adv="1">20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1637" adv="1">1637</ref>
    </refs>
    <vuln_soft>
      <prod name="xs4all_data_sunftp" vendor="xs4all_data">
        <vers num="1.0_build_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0856" seq="2000-0856" published="2000-11-14" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html" adv="1">20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1638" adv="1">1638</ref>
    </refs>
    <vuln_soft>
      <prod name="xs4all_data_sunftp" vendor="xs4all_data">
        <vers num="1.0_build_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0857" seq="2000-0857" published="2000-11-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0067.html" adv="1">20000909 format string bug in muh</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0068.html" adv="1">20000909 Re: format string bug in muh</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1665" adv="1" patch="1">1665</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5215">muh-log-dos(5215)</ref>
    </refs>
    <vuln_soft>
      <prod name="muh" vendor="sebastian_kienzl">
        <vers num="2.05d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0858" seq="2000-0858" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0065.html" adv="1" patch="1">MS00-063</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80413" adv="1" patch="1">20000906 VIGILANTE-2000009: "Invalid URL" DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1642" adv="1" patch="1">1642</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5202">iis-invald-url-dos(5202)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0859" seq="2000-0859" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0471.html" adv="1" patch="1">20000904 VIGILANTE-2000008: NTMail Configuration Service DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1640" adv="1" patch="1">1640</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5182">ntmail-incomplete-http-requests(5182)</ref>
    </refs>
    <vuln_soft>
      <prod name="ntmail" vendor="gordano">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0860" seq="2000-0860" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0455.html" adv="1">20000903 (SRADV00001) Arbitrary file disclosure through PHP file upload</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0477.html">20000904 Re: [PHP-DEV] RE: (SRADV00001) Arbitrary file disclosure through PHP file upload</ref>
      <ref source="MANDRAKE" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0150.html">MDKSA-2000:048</ref>
      <ref source="CONFIRM" url="http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&amp;tr1=1.1&amp;r2=text&amp;tr2=1.45&amp;diff_format=u">http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&amp;tr1=1.1&amp;r2=text&amp;tr2=1.45&amp;diff_format=u</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1649" adv="1">1649</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5190">php-file-upload(5190)</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="2.0b10"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0861" seq="2000-0861" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0040.html" adv="1" patch="1">20000907 Mailman 1.1 + external archiver vulnerability</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0112.html" adv="1" patch="1">FreeBSD-SA-00:51</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1667" adv="1" patch="1">1667</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5493">mailman-execute-external-commands(5493)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0862" seq="2000-0862" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0059.html" adv="1">ASB00-23</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5466">allaire-spectra-admin-access(5466)</ref>
    </refs>
    <vuln_soft>
      <prod name="spectra" vendor="allaire">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0863" seq="2000-0863" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0111.html" adv="1" patch="1">FreeBSD-SA-00:50</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5503">listmanager-port-bo(5503)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="listmanager">
        <vers num="2.96" prev="1"/>
        <vers num="2.97"/>
        <vers num="2.98"/>
        <vers num="2.99"/>
        <vers num="2.100"/>
        <vers num="2.101"/>
        <vers num="2.102"/>
        <vers num="2.103"/>
        <vers num="2.104"/>
        <vers num="2.105.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0864" seq="2000-0864" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a  symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0095.html">20000911 Patch for esound-0.2.19</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0118.html">20001006 Immunix OS Security Update for esound</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0365.html" adv="1">FreeBSD-SA-00:45</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001008">20001008 esound: race condition</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/esound_daemon_race_condition.html">20001012 esound daemon race condition</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-077.html">RHSA-2000:077</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1659" adv="1" patch="1">1659</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5213">gnome-esound-symlink(5213)</ref>
    </refs>
    <vuln_soft>
      <prod name="esound" vendor="gnome">
        <vers num="0.2.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0865" seq="2000-0865" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0185.html" adv="1" patch="1">20000916 Advisory: Tridia DoubleVision / SCO UnixWare</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1697" adv="1" patch="1">1697</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5261">doublevision-dvtermtype-bo(5261)</ref>
    </refs>
    <vuln_soft>
      <prod name="doublevision" vendor="tridia">
        <vers num="3.07.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0866" seq="2000-0866" published="2000-11-14" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0027.html">20000907 SEGFAULTING Interbase 6 SS Linux</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1654" adv="1">1654</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5205">interbase-query-dos(5205)</ref>
    </refs>
    <vuln_soft>
      <prod name="interbase_superserver" vendor="borland_software">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0867" seq="2000-0867" published="2000-11-14" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-032.0.txt">CSSA-2000-032.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0193.html" adv="1">20000917 klogd format bug</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:050">MDKSA-2000:050</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97726239017741&amp;w=2">20000918 Conectiva Linux Security Announcement - sysklogd</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv9_draht_syslogd_txt.html">20000920 syslogd + klogd format string parsing error</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-061.html">RHSA-2000:061</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000023.html">TLSA2000022-2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5259">klogd-format-string(5259)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1" edition=":slink"/>
        <vers num="2.2" edition=":potato"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
        <vers num="6.2"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num=""/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0868" seq="2000-0868" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html" adv="1" patch="1">20000907</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090700-2.txt" adv="1" patch="1">A090700-2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1658" adv="1" patch="1">1658</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5197">suse-apache-cgi-source-code(5197)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.12"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0869" seq="2000-0869" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html" adv="1">20000907</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090700-3.txt" adv="1">A090700-3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1656" adv="1" patch="1">1656</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5204">apache-webdav-directory-listings(5204)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.12"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1" edition="alpha"/>
        <vers num="6.2"/>
        <vers num="6.3" edition=":ppc"/>
        <vers num="6.3" edition="alpha"/>
        <vers num="6.4" edition=":ppc"/>
        <vers num="6.4" edition="alpha"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0870" seq="2000-0870" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html" adv="1">20000911[EXPL] EFTP vulnerable to two DoS attacks</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1675" adv="1">1675</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5219">eftp-bo(5219)</ref>
    </refs>
    <vuln_soft>
      <prod name="eftp" vendor="khamil_landross_and_zack_jones">
        <vers num="2.0.4.281"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0871" seq="2000-0871" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html" adv="1">20000911[EXPL] EFTP vulnerable to two DoS attacks</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1677" adv="1">1677</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5220">eftp-newline-dos(5220)</ref>
    </refs>
    <vuln_soft>
      <prod name="eftp" vendor="khamil_landross_and_zack_jones">
        <vers num="2.0.4.281"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0872" seq="2000-0872" published="2000-11-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0015.html" adv="1">20000906 PhotoAlbum 0.9.9 explorer.php Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1650" adv="1">1650</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5198">phpphoto-dir-traverse(5198)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpphotoalbum" vendor="nathan_purciful">
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0873" seq="2000-0873" published="2000-11-14" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0454.html" adv="1">20000903 aix allows clearing the interface stats</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1660">1660</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5214">aix-clear-netstat(5214)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0874" seq="2000-0874" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80888" adv="1">20000907 Eudora disclosure</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1653" adv="1">1653</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5206">eudora-path-disclosure(5206)</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0875" seq="2000-0875" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html" adv="1">20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref>
      <ref source="CONFIRM" url="http://www.wftpd.com/bug_gpf.htm">http://www.wftpd.com/bug_gpf.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5194">wftpd-long-string-dos(5194)</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
        <vers num="2.4.1_rc11"/>
        <vers num="2.4.1_rc12"/>
        <vers num="2.34"/>
        <vers num="2.40"/>
      </prod>
      <prod name="wftpd_pro" vendor="texas_imperial_software">
        <vers num="2.41_rc12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0876" seq="2000-0876" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the  full pathname of the server via a "%C" command, which generates an error message that includes the pathname.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html">20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5196">wftpd-path-disclosure(5196)</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
        <vers num="2.4.1_rc11"/>
        <vers num="2.4.1_rc12"/>
        <vers num="2.34"/>
        <vers num="2.40"/>
      </prod>
      <prod name="wftpd_pro" vendor="texas_imperial_software">
        <vers num="2.41_rc12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0877" seq="2000-0877" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0092.html" adv="1">20000911 Unsafe passing of variables to mailform.pl in MailForm V2.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1670" adv="1">1670</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5224">mailform-attach-file(5224)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailform" vendor="ranson_johnson">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0878" seq="2000-0878" published="2000-11-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0088.html" adv="1" patch="1">20000911 Fwd: Poor variable checking in mailto.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1669" adv="1" patch="1">1669</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5241">mailto-piped-address(5241)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailto_cgi_script" vendor="ranson_johnson">
        <vers num="1.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0879" seq="2000-0879" published="2000-11-14" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html" adv="1">20000906 Multiple Security Holes in LPPlus</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1643" adv="1">1643</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5199">lpplus-permissions-dos(5199)</ref>
    </refs>
    <vuln_soft>
      <prod name="lpplus" vendor="plus_technologies">
        <vers num="3.2.2"/>
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0880" seq="2000-0880" published="2000-11-14" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html" adv="1">20000906 Multiple Security Holes in LPPlus</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1643" adv="1">1643</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5200">lpplus-process-perms-dos(5200)</ref>
    </refs>
    <vuln_soft>
      <prod name="lpplus" vendor="plus_technologies">
        <vers num="3.2.2"/>
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0881" seq="2000-0881" published="2000-11-14" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html" adv="1">20000906 Multiple Security Holes in LPPlus</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1644" adv="1">1644</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5201">lpplus-dccscan-file-read(5201)</ref>
    </refs>
    <vuln_soft>
      <prod name="lpplus" vendor="plus_technologies">
        <vers num="3.2.2"/>
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0882" seq="2000-0882" published="2000-11-14" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0533.html" adv="1" patch="1">20000906 VIGILANTE-2000010: Intel Express Switch series 500 DoS #2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1647" adv="1" patch="1">1647</ref>
    </refs>
    <vuln_soft>
      <prod name="express_510t" vendor="intel">
        <vers num="2.63"/>
        <vers num="2.64"/>
      </prod>
      <prod name="express_520t" vendor="intel">
        <vers num="2.63"/>
        <vers num="2.64"/>
      </prod>
      <prod name="express_550f" vendor="intel">
        <vers num="2.63"/>
        <vers num="2.64"/>
      </prod>
      <prod name="express_550t" vendor="intel">
        <vers num="2.63"/>
        <vers num="2.64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0883" seq="2000-0883" published="2000-11-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0111.html" adv="1" patch="1">MDKSA-2000:046</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1678" adv="1" patch="1">1678</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5257">linux-mod-perl(5257)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0884" seq="2000-0884" published="2000-12-19" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1806">1806</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-078">MS00-078</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5377">iis-unicode-translation(5377)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A44">oval:org.mitre.oval:def:44</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0885" seq="2000-0885" published="2000-12-19" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability.  NOTE: It is highly likely that this candidate will be split into multiple candidates.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-083">MS00-083</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5399">network-monitor-bo(5399)</ref>
    </refs>
    <vuln_soft>
      <prod name="systems_management_server" vendor="microsoft">
        <vers num="1.2"/>
        <vers num="2.0"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0886" seq="2000-0886" published="2000-12-19" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1912">1912</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?mid=143604&amp;list=1&amp;fromthread=0&amp;end=2000-11-11&amp;threads=0&amp;start=2000-11-05&amp;" adv="1">20001107 NSFOCUS SA2000-07 : Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-086">MS00-086</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5470">iis-invalid-filename-passing(5470)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A191">oval:org.mitre.oval:def:191</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0887" seq="2000-0887" published="2000-12-19" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html">SuSE-SA:2000:45</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338">CLSA-2000:338</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339" adv="1" patch="1">CLSA-2000:339</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067">MDKSA-2000:067</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-20.html">CA-2000-20</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001112">20001112 bind: remote Denial of Service</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-107.html">RHSA-2000:107</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143843">20001107 BIND 8.2.2-P5 Possible DOS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1923" adv="1" patch="1">1923</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5540">bind-zxfr-dos(5540)</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.2.2" edition="p5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0888" seq="2000-0888" published="2000-12-19" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html">SuSE-SA:2000:45</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338">CLSA-2000:338</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339" adv="1" patch="1">CLSA-2000:339</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067">MDKSA-2000:067</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-20.html" adv="1">CA-2000-20</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001112">20001112 bind: remote Denial of Service</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-107.html">RHSA-2000:107</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5814">bind-srv-dos(5814)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2000-0889" seq="2000-0889" published="2001-02-12" modified="2005-10-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/198&amp;type=0&amp;nav=sec.sba" adv="1">00198</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-19.html" adv="1" patch="1">CA-2000-19</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2000-0890" seq="2000-0890" published="2001-02-16" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/626919" adv="1" patch="1">VU#626919</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2325">2325</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6047">periodic-temp-file-symlink(6047)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0891" seq="2000-0891" published="2001-07-21" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/5962" adv="1" patch="1">VU#5962</ref>
      <ref source="CONFIRM" url="http://www.notes.net/R5FixList.nsf/Search!SearchView&amp;Query=CBAT45TU9S">http://www.notes.net/R5FixList.nsf/Search!SearchView&amp;Query=CBAT45TU9S</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5045">lotus-notes-bypass-ecl(5045)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_notes" vendor="ibm">
        <vers num="5.02" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0892" seq="2000-0892" published="2001-07-21" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/22404" adv="1" patch="1">VU#22404</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6644">telnet-obtain-env-variable(6644)</ref>
    </refs>
    <vuln_soft>
      <prod name="u_win" vendor="u_win">
        <vers num=""/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0893" seq="2000-0893" published="2001-02-16" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/28027" adv="1" patch="1">VU#28027</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0894" seq="2000-0894" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2119" adv="1" patch="1">2119</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise70.php" adv="1" patch="1">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5554">watchguard-soho-web-auth(5554)</ref>
    </refs>
    <vuln_soft>
      <prod name="soho_firewall" vendor="watchguard">
        <vers num="1.6"/>
        <vers num="2.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0895" seq="2000-0895" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2114" adv="1" patch="1">2114</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise70.php" adv="1" patch="1">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5218">watchguard-soho-web-dos(5218)</ref>
    </refs>
    <vuln_soft>
      <prod name="soho_firewall" vendor="watchguard">
        <vers num="1.6"/>
        <vers num="2.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0896" seq="2000-0896" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2113" adv="1" patch="1">2113</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise70.php" adv="1" patch="1">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5749">watchguard-soho-fragmented-packets(5749)</ref>
    </refs>
    <vuln_soft>
      <prod name="soho_firewall" vendor="watchguard">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0897" seq="2000-0897" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://home.lanck.net/mf/srv/index.htm">http://home.lanck.net/mf/srv/index.htm</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97421834001092&amp;w=2">20001114 Vulnerabilites in SmallHTTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1941" adv="1" patch="1">1941</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5524">small-http-nofile-dos(5524)</ref>
    </refs>
    <vuln_soft>
      <prod name="small_http_server" vendor="max_feoktistov">
        <vers num="2.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0898" seq="2000-0898" published="2001-01-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97421834001092&amp;w=2">20001114 Vulnerabilites in SmallHTTP Server</ref>
    </refs>
    <vuln_soft>
      <prod name="small_http_server" vendor="max_feoktistov">
        <vers num="2.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0899" seq="2000-0899" published="2001-01-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97421834001092&amp;w=2">20001114 Vulnerabilites in SmallHTTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1942" adv="1" patch="1">1942</ref>
    </refs>
    <vuln_soft>
      <prod name="small_http_server" vendor="max_feoktistov">
        <vers num="2.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0900" seq="2000-0900" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:73.thttpd.asc">FreeBSD-SA-00:73</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0025.html" adv="1">20001002 thttpd ssi: retrieval of arbitrary world-readable files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1737" adv="1">1737</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5313">acme-thttpd-ssi(5313)</ref>
    </refs>
    <vuln_soft>
      <prod name="thttpd" vendor="acme_labs">
        <vers num="2.16"/>
        <vers num="2.17"/>
        <vers num="2.18"/>
        <vers num="2.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0901" seq="2000-0901" published="2000-12-19" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:46.screen.asc">FreeBSD-SA-00:46</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0530.html">20000906 Screen-3.7.6 local compromise</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-044.php3">MDKSA-2000:044</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv6_draht_screen_txt.html">20000906 screen format string parsing security problem</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-058.html">RHSA-2000:058</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80178">20000905 screen 3.9.5 root vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1641" adv="1" patch="1">1641</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5188">screen-format-string(5188)</ref>
    </refs>
    <vuln_soft>
      <prod name="weigert_screen" vendor="juergen">
        <vers num="3.9.3"/>
        <vers num="3.9.4"/>
        <vers num="3.9.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0902" seq="2000-0902" published="2000-12-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80858">20000907 Re: PhotoAlbum 0.9.9 explorer.php Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5209">phpphotoalbum-getalbum-directory-traversal(5209)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpphotoalbum" vendor="nathan_purciful">
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0903" seq="2000-0903" published="2000-12-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/79956" adv="1">20000901 Multiple QNX Voyager Issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1648" adv="1">1648</ref>
    </refs>
    <vuln_soft>
      <prod name="voyager" vendor="qnx">
        <vers num="2.01b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0904" seq="2000-0904" published="2000-12-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/79956" adv="1">20000901 Multiple QNX Voyager Issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1648" adv="1">1648</ref>
    </refs>
    <vuln_soft>
      <prod name="voyager" vendor="qnx">
        <vers num="2.01b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0905" seq="2000-0905" published="2000-12-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/79956" adv="1">20000901 Multiple QNX Voyager Issues</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1648" adv="1">1648</ref>
    </refs>
    <vuln_soft>
      <prod name="voyager" vendor="qnx">
        <vers num="2.01b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0906" seq="2000-0906" published="2000-12-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0013.html" adv="1" patch="1">20001002 Moreover Cached_Feed CGI Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1762" adv="1" patch="1">1762</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5334">moreover-cgi-dir-traverse(5334)</ref>
    </refs>
    <vuln_soft>
      <prod name="cached_feed.cgi_script" vendor="moreover.com">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0907" seq="2000-0907" published="2000-12-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0131.html" adv="1" patch="1">20000925 DST2K0030: DoS in EServ 2.92 Build 2982</ref>
    </refs>
    <vuln_soft>
      <prod name="eserv" vendor="etype">
        <vers num="2.92"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0908" seq="2000-0908" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0128.html">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96956211605302&amp;w=2">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref>
      <ref source="CONFIRM" url="http://www.netcplus.com/browsegate.htm#BGLatest">http://www.netcplus.com/browsegate.htm#BGLatest</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1702" adv="1" patch="1">1702</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5270">browsegate-http-dos(5270)</ref>
    </refs>
    <vuln_soft>
      <prod name="browsegate" vendor="netcplus">
        <vers num="2.80"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0909" seq="2000-0909" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:59.pine.asc">FreeBSD-SA-00:59</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0441.html">20001031 FW: Pine 4.30 now available</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-073.php3">MDKSA-2000:073</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-102.html">RHSA-2000:102</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84901">20000922  [ no subject ]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1709" adv="1" patch="1">1709</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5283">pine-check-mail-bo(5283)</ref>
    </refs>
    <vuln_soft>
      <prod name="pine" vendor="university_of_washington">
        <vers num="4.0.4"/>
        <vers num="4.10"/>
        <vers num="4.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0910" seq="2000-0910" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the "from" address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0051.html">20000908 horde library bug - unchecked from-address</ref>
      <ref source="CONFIRM" url="http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch">http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000910" adv="1" patch="1">20000910 imp: remote compromise</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1674" adv="1" patch="1">1674</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5278">horde-imp-sendmail-command(5278)</ref>
    </refs>
    <vuln_soft>
      <prod name="horde" vendor="horde">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0911" seq="2000-0911" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/82088" adv="1" patch="1">20000912  (SRADV00003) Arbitrary file disclosure through IMP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1679" adv="1" patch="1">1679</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5227">imp-attach-file(5227)</ref>
    </refs>
    <vuln_soft>
      <prod name="imp" vendor="horde">
        <vers num="2.0"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0912" seq="2000-0912" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0146.html" adv="1">20000913 MultiHTML vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5285">http-cgi-multihtml(5285)</ref>
    </refs>
    <vuln_soft>
      <prod name="multihtml" vendor="jcs_web_works">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0913" seq="2000-0913" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html">20000929 Security vulnerability in Apache mod_rewrite</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0174.html">20001011 Conectiva Linux Security Announcement - apache</ref>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0021.html">HPSBUX0010-126</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-035.0.txt">CSSA-2000-035.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-060-2.php3?dis=7.1">MDKSA-2000:060</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-088.html">RHSA-2000:088</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-095.html">RHSA-2000:095</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1728" adv="1" patch="1">1728</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5310">apache-rewrite-view-files(5310)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="0.8.11"/>
        <vers num="0.8.14"/>
        <vers num="1.0"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.5"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.3.11" edition=":win32"/>
        <vers num="1.3.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0914" seq="2000-0914" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0078.html" adv="1" patch="1">20001005 obsd_fun.c</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1759" adv="1" patch="1">1759</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5340">bsd-arp-request-dos(5340)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0915" seq="2000-0915" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:54.fingerd.asc">FreeBSD-SA-00:54</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0017.html">20001002 [sa2c@and.or.jp: bin/21704: enabling fingerd makes files world readable]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1803" adv="1" patch="1">1803</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5385">freebsd-fingerd-files(5385)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.1.1" edition="release"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0916" seq="2000-0916" published="2000-12-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.asc" adv="1" patch="1">FreeBSD-SA-00:52</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1766" adv="1" patch="1">1766</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0917" seq="2000-0917" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:56.lprng.asc">FreeBSD-SA-00:56</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0293.html">20000925 Format strings: bug #2: LPRng</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-033.0.txt">CSSA-2000-033.0</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-22.html">CA-2000-22</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-065.html">RHSA-2000:065</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1712" adv="1" patch="1">1712</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5287">lprng-format-string(5287)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_ebuilder" vendor="caldera">
        <vers num="3.0"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0918" seq="2000-0918" published="2000-12-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/83914" patch="1">20000919 kvt format bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1700" adv="1" patch="1">1700</ref>
    </refs>
    <vuln_soft>
      <prod name="kvt" vendor="kde">
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0919" seq="2000-0919" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0117.html">20001007 PHPix advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1773" adv="1">1773</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5331">phpix-dir-traversal(5331)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpix" vendor="phpix">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0920" seq="2000-0920" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:60.boa.asc">FreeBSD-SA-00:60</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0092.html">20001006 Vulnerability in BOA web server v0.94.8.2</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001009">20001009 boa: exposes contents of local files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1770" adv="1" patch="1">1770</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5330">boa-webserver-get-dir-traversal(5330)</ref>
    </refs>
    <vuln_soft>
      <prod name="boa_webserver" vendor="boa">
        <vers num="0.94.8.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0921" seq="2000-0921" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0115.html">20001007 Security Advisory: Hassan Consulting's shop.cgi Directory Traversal Vulnerability.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1777" adv="1" patch="1">1777</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5342">hassan-shopping-cart-dir-traversal(5342)</ref>
    </refs>
    <vuln_soft>
      <prod name="shopping_cart" vendor="hassan_consulting">
        <vers num="1.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0922" seq="2000-0922" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0120.html">20001008 Security Advisory: Bytes Interactive's Web Shopper (shopper.cgi) Directory Traversal Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1776" adv="1" patch="1">1776</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5351">web-shopper-directory-traversal(5351)</ref>
    </refs>
    <vuln_soft>
      <prod name="web_shopper" vendor="bytes_interactive">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0923" seq="2000-0923" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0107.html" adv="1">20001006 Fwd: APlio PRO web shell</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1784" adv="1">1784</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5333">uclinux-apliophone-bin-execute(5333)</ref>
    </refs>
    <vuln_soft>
      <prod name="aplio_phone" vendor="aplio">
        <vers num="2.0.33_build1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0924" seq="2000-0924" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catigory" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0141.html" adv="1">20001009 Master Index traverse advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1772" adv="1">1772</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5355">master-index-directory-traversal(5355)</ref>
    </refs>
    <vuln_soft>
      <prod name="master_index" vendor="armada_design">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0925" seq="2000-0925" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0001.html" adv="1" patch="1">20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97050819812055&amp;w=2">20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1734" adv="1" patch="1">1734</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5318">cyberoffice-world-readable-directory(5318)</ref>
    </refs>
    <vuln_soft>
      <prod name="cyberoffice_shopping_cart" vendor="smartwin_technology">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0926" seq="2000-0926" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the "Price" hidden form variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0000.html" adv="1" patch="1">20001002 DST2K0036: Price modification possible in CyberOffice Shopping Ca rt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97050627707128&amp;w=2">20001002 DST2K0036: Price modification possible in CyberOffice Shopping Cart</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1733" adv="1" patch="1">1733</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5319">cyberoffice-price-modification(5319)</ref>
    </refs>
    <vuln_soft>
      <prod name="cyberoffice_shopping_cart" vendor="smartwin_technology">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0927" seq="2000-0927" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09//0331.html">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0173.html">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1724" adv="1">1724</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5302">quotaadvisor-quota-bypass(5302)</ref>
    </refs>
    <vuln_soft>
      <prod name="quotaadvisor" vendor="wquinn">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0928" seq="2000-0928" published="2000-12-19" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0091.html" adv="1">20001006 DST2K0040: QuotaAdvisor 4.1 by WQuinn susceptible to any user bei ng able to list (not read) all files on any server running QuotaAdvisor.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1765" adv="1">1765</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5327">quotaadvisor-list-files(5327)</ref>
    </refs>
    <vuln_soft>
      <prod name="diskadvisor" vendor="wquinn">
        <vers num="4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0929" seq="2000-0929" published="2000-12-19" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97024839222747&amp;w=2">20000929 Malformed Embedded Windows Media Player 7 "OCX Attachment"</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1714" adv="1" patch="1">1714</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-068">MS00-068</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5309">mediaplayer-outlook-dos(5309)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0930" seq="2000-0930" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html">20001003 Pegasus mail file reading vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html" adv="1">20001030 Pegasus Mail file reading vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1738" adv="1" patch="1">1738</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5326">pegasus-file-forwarding(5326)</ref>
    </refs>
    <vuln_soft>
      <prod name="pegasus_mail" vendor="david_harris">
        <vers num="3.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0931" seq="2000-0931" published="2000-12-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/137518" adv="1">20001004 Another Pegasus Mail vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1750" adv="1">1750</ref>
    </refs>
    <vuln_soft>
      <prod name="pegasus_mail" vendor="david_harris">
        <vers num="3.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0932" seq="2000-0932" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0181.html">20000926 FW: DOS for Content Technologies' MAILsweeper for SMTP.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5641">mailsweeper-smtp-dos(5641)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper_for_smtp" vendor="clearswift">
        <vers num="3.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0933" seq="2000-0933" published="2000-12-19" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recognition" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1729" adv="1" patch="1">1729</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-069">MS00-069</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5301">win2k-simplified-chinese-ime(5301)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0934" seq="2000-0934" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-062.html">RHSA-2000:062</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1703" adv="1" patch="1">1703</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5271">glint-symlink(5271)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0935" seq="2000-0935" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" adv="1" patch="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1872" adv="1" patch="1">1872</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5443">samba-swat-logging-sym-link(5443)</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0936" seq="2000-0936" published="2000-12-19" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" adv="1" patch="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1874" adv="1" patch="1">1874</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5445">samba-swat-logfile-info(5445)</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0937" seq="2000-0937" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" adv="1" patch="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1873" adv="1">1873</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5442">samba-swat-brute-force(5442)</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0938" seq="2000-0938" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" adv="1" patch="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5442">samba-swat-brute-force(5442)</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0939" seq="2000-0939" published="2000-12-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html" adv="1" patch="1">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5444">samba-swat-url-filename-dos(5444)</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0940" seq="2000-0940" published="2000-12-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0422.html" adv="1">20001029 Minor bug in Pagelog.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1864" adv="1">1864</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5451">pagelog-cgi-dir-traverse(5451)</ref>
    </refs>
    <vuln_soft>
      <prod name="pagelog.cgi" vendor="metertek">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0941" seq="2000-0941" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "whois" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html">20001029 Remote command execution via KW Whois 1.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.html" adv="1" patch="1">20001029 Re: Remote command execution via KW Whois 1.0 (addition)</ref>
      <ref source="MISC" url="http://www.kootenayweb.bc.ca/scripts/whois.txt">http://www.kootenayweb.bc.ca/scripts/whois.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1883" adv="1" patch="1">1883</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5438">kw-whois-meta(5438)</ref>
    </refs>
    <vuln_soft>
      <prod name="kootenay_web_inc_whois" vendor="kootenay_web_inc">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0942" seq="2000-0942" published="2000-12-19" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141903">20001028 IIS 5.0 cross site scripting vulnerability - using .htw</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1861" adv="1" patch="1">1861</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-084">MS00-084</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5441">iis-htw-cross-scripting(5441)</ref>
    </refs>
    <vuln_soft>
      <prod name="indexing_service" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0943" seq="2000-0943" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0397.html" adv="1" patch="1">20001027 Potential Security Problem in bftpd-1.0.11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1858">1858</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5426">bftpd-user-bo(5426)</ref>
    </refs>
    <vuln_soft>
      <prod name="bftpd" vendor="max-wilhelm_bruker">
        <vers num="1.0.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0944" seq="2000-0944" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0402.html" adv="1">20001027 CGI-Bug: News Update 1.1 administration password bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1881" adv="1">1881</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5433">news-update-bypass-password(5433)</ref>
    </refs>
    <vuln_soft>
      <prod name="news_update" vendor="cgi_script_center">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0945" seq="2000-0945" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html" adv="1">20001026 Advisory def-2000-02: Cisco Catalyst remote command execution</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0194.html">20001113 Re: 3500XL</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1846" adv="1" patch="1">1846</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5415">cisco-catalyst-remote-commands(5415)</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_3500_xl" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0946" seq="2000-0946" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0023.html" adv="1" patch="1">20001012 Security issue with Compaq Easy Access Keyboard software</ref>
      <ref source="CONFIRM" url="http://www5.compaq.com/support/files/desktops/us/revision/1723.html">http://www5.compaq.com/support/files/desktops/us/revision/1723.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5718">compaq-ea-elevate-privileges(5718)</ref>
    </refs>
    <vuln_soft>
      <prod name="easy_access_keyboard_software" vendor="compaq">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0947" seq="2000-0947" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-013.txt.asc">NetBSD-SA2000-013</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0004.html">20001002 Very probable remote root vulnerability in cfengine</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-061.php3?dis=7.1" adv="1" patch="1">MDKSA-2000:061</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1757" adv="1" patch="1">1757</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5630">cfengine-cfd-format-string(5630)</ref>
    </refs>
    <vuln_soft>
      <prod name="cfengine" vendor="gnu">
        <vers num="1.5"/>
        <vers num="1.5.3-4"/>
        <vers num="1.6" edition="a10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0948" seq="2000-0948" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0043.html">20001003 Conectiva Linux Security Announcement - gnorpm</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0184.html">20001011 Immunix OS Security Update for gnorpm package</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-055.php3?dis=7.0">MDKSA-2000:055</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-072.html">RHSA-2000:072</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/136866">20001002 GnoRPM local /tmp vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1761" adv="1" patch="1">1761</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5317">gnorpm-temp-symlink(5317)</ref>
    </refs>
    <vuln_soft>
      <prod name="gnorpm" vendor="gnome">
        <vers num="0.94" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0949" seq="2000-0949" published="2000-12-19" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0344.html">20000928 Very interesting traceroute flaw</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0357.html">20000930 Conectiva Linux Security Announcement - traceroute</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-034.0.txt">CSSA-2000-034.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001013">20001013 traceroute: local root exploit</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-053.php3?dis=7.1">MDKSA-2000:053</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-078.html">RHSA-2000:078</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1739" adv="1" patch="1">1739</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-October/000025.html">TLSA2000023-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5311">traceroute-heap-overflow(5311)</ref>
    </refs>
    <vuln_soft>
      <prod name="lbl_traceroute" vendor="lbl">
        <vers num="1.4a5"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0950" seq="2000-0950" published="2000-12-19" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0376.html" adv="1" patch="1">20001026 FWTK x-gw Security Advisory [GSA2000-01]</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5420">tisfwtk-xgw-execute-code(5420)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_firewall_toolkit" vendor="tis">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0951" seq="2000-0951" published="2000-12-19" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100400-1.txt">A100400-1</ref>
      <ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=272079">Q272079</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1756" adv="1" patch="1">1756</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5335">iis-index-dir-traverse(5335)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0952" seq="2000-0952" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-014.txt.asc" adv="1" patch="1">NetBSD-SA2000-014</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5424">global-execute-remote-commands(5424)</ref>
    </refs>
    <vuln_soft>
      <prod name="global" vendor="shigio_yamaguchi">
        <vers num="3.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0953" seq="2000-0953" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html" adv="1">20001009 Shambala 4.5 vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1778" adv="1">1778</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5345">shambala-connection-dos(5345)</ref>
    </refs>
    <vuln_soft>
      <prod name="shambala_server" vendor="evolvable_corporation">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0954" seq="2000-0954" published="2000-12-19" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html" adv="1">20001009 Shambala 4.5 vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1771" adv="1">1771</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5346">shambala-password-plaintext(5346)</ref>
    </refs>
    <vuln_soft>
      <prod name="shambala_server" vendor="evolvable_corporation">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0955" seq="2000-0955" published="2000-12-19" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a102600-1.txt" adv="1" patch="1">A102600-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1885" adv="1" patch="1">1885</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5425">cisco-vco-snmp-passwords(5425)</ref>
    </refs>
    <vuln_soft>
      <prod name="virtual_central_office_4000" vendor="cisco">
        <vers num="5.1.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0956" seq="2000-0956" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-094.html" adv="1" patch="1">RHSA-2000:094</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1875" adv="1" patch="1">1875</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5427">cyrus-sasl-gain-access(5427)</ref>
    </refs>
    <vuln_soft>
      <prod name="cyrus-sasl" vendor="carnegie_mellon_university">
        <vers num="1.5.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0957" seq="2000-0957" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0374.html" adv="1" patch="1">20001026 (SRADV00004) Remote and local vulnerabilities in pam_mysql</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5447">pammysql-auth-input(5447)</ref>
    </refs>
    <vuln_soft>
      <prod name="pam_mysql" vendor="pam_mysql">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0958" seq="2000-0958" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0349.html" adv="1" patch="1">20001025 HotJava Browser 3.0 JavaScript security vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5428">hotjava-browser-dom-access(5428)</ref>
    </refs>
    <vuln_soft>
      <prod name="hotjava_browser" vendor="sun">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0959" seq="2000-0959" published="2000-12-19" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/85028">20000926 ld.so bug - LD_DEBUG_OUTPUT follows symlinks</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1719" adv="1">1719</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5299">glibc-unset-symlink(5299)</ref>
    </refs>
    <vuln_soft>
      <prod name="glibc" vendor="gnu">
        <vers num="2.1.3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0960" seq="2000-0960" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97138100426121&amp;w=2">20001011 Netscape Messaging server 4.15 poor error strings</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1787" adv="1">1787</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5364">netscape-messaging-email-verify(5364)</ref>
    </refs>
    <vuln_soft>
      <prod name="messaging_server" vendor="netscape">
        <vers num="4.15" edition="patch1"/>
        <vers num="4.15" edition="patch2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0961" seq="2000-0961" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0334.html">20000928 commercial products and security [ + new bug ]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1721" adv="1">1721</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5292">netscape-messaging-list-dos(5292)</ref>
    </refs>
    <vuln_soft>
      <prod name="messaging_server" vendor="netscape">
        <vers num="4.0"/>
      </prod>
      <prod name="netscape_messaging_server_multiplexor" vendor="netscape">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0962" seq="2000-0962" published="2000-12-19" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0299.html" adv="1" patch="1">20000925 Nmap Protocol Scanning DoS against OpenBSD IPSEC</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1723" adv="1" patch="1">1723</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5634">openbsd-nmap-dos(5634)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0963" seq="2000-0963" published="2000-12-19" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-036.0.txt" adv="1" patch="1">CSSA-2000-036.0</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/138550">20001009 ncurses buffer overflows</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1142" adv="1" patch="1">1142</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/44487">gnu-ncurses-term-terminfodirs-bo(44487)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.4"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="stable"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0964" seq="2000-0964" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0336.html">20000928 Another thingy.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1727" adv="1">1727</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5298">hinet-ipphone-get-bo(5298)</ref>
    </refs>
    <vuln_soft>
      <prod name="hinet_lp" vendor="siemens">
        <vers num="5100.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0965" seq="2000-0965" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0012.html" adv="1" patch="1">HPSBUX0010-124</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5361">hp-virtualvault-nsapi-dos(5361)</ref>
    </refs>
    <vuln_soft>
      <prod name="vvos" vendor="hp">
        <vers num="10.24"/>
        <vers num="11.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0966" seq="2000-0966" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0020.html" adv="1" patch="1">HPSBUX0010-125</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5379">hp-lpspooler-bo(5379)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0967" seq="2000-0967" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:75.php.asc">FreeBSD-SA-00:75</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0204.html">20001012 Conectiva Linux Security Announcement - mod_php3</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a101200-1.txt">A101200-1</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-037.0.txt">CSSA-2000-037.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-062.php3?dis=7.1">MDKSA-2000:062</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-088.html">RHSA-2000:088</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-095.html">RHSA-2000:095</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1786" adv="1" patch="1">1786</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5359">php-logging-format-string(5359)</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0968" seq="2000-0968" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html">20001016 Half-Life Dedicated Server Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html">20001027 Re: Half Life dedicated server Patch</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141060">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1799" adv="1" patch="1">1799</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5375">halflife-server-changelevel-bo(5375)</ref>
    </refs>
    <vuln_soft>
      <prod name="half-life_dedicated_server" vendor="valve_software">
        <vers num="3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0969" seq="2000-0969" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html">20001016 Half-Life Dedicated Server Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html">20001027 Re: Half Life dedicated server Patch</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141060">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5413">halflife-rcon-format-string(5413)</ref>
    </refs>
    <vuln_soft>
      <prod name="half-life_dedicated_server" vendor="valve_software">
        <vers num="3.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0970" seq="2000-0970" published="2000-12-19" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-080">MS00-080</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5396">session-cookie-remote-retrieval(5396)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0971" seq="2000-0971" published="2000-12-19" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0301.html" adv="1">20001023 Avirt Mail 4.x DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5397">avirt-mail-from-dos(5397)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5398">avirt-rcpt-to-dos(5398)</ref>
    </refs>
    <vuln_soft>
      <prod name="avirt_mail_server" vendor="avirt">
        <vers num="4.0"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0972" seq="2000-0972" published="2000-12-19" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0317.html" adv="1">20001020 [ Hackerslab bug_paper ] HP-UX crontab temporary file symbolic link vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5410">hp-crontab-read-files(5410)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0973" seq="2000-0973" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:72.curl.asc">FreeBSD-SA-00:72</ref>
      <ref source="REDHAT" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0331.html">RHBA-2000:092-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1804" adv="1" patch="1">1804</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5374">curl-error-bo(5374)</ref>
    </refs>
    <vuln_soft>
      <prod name="curl" vendor="daniel_stenberg">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.1beta"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.1"/>
        <vers num="7.1.1"/>
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0974" seq="2000-0974" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-038.0.txt">CSSA-2000-038.0</ref>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:67.gnupg.asc">FreeBSD-SA-00:67</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0201.html">20001011 GPG 1.0.3 doesn't detect modifications to files with multiple signatures</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0361.html">20001025 Immunix OS Security Update for gnupg package</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000334">CLSA-2000:334</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001111">20001111 gnupg: incorrect signature verification</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-089.html">RHSA-2000:089</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1797" adv="1" patch="1">1797</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5386">gnupg-message-modify(5386)</ref>
    </refs>
    <vuln_soft>
      <prod name="privacy_guard" vendor="gnu">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0975" seq="2000-0975" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0210.html" adv="1">20001012 Anaconda Advisory</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5750">anaconda-apexec-directory-traversal(5750)</ref>
    </refs>
    <vuln_soft>
      <prod name="foundation_directory" vendor="anaconda_partners">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0976" seq="2000-0976" published="2000-12-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020502-01-I">20020502-01-I</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0211.html" adv="1">20001012 another Xlib buffer overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5751.php">xfree-xlib-bo(5751)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1805" adv="1">1805</ref>
    </refs>
    <vuln_soft>
      <prod name="xlib" vendor="xfree86_project">
        <vers num="3.3x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0977" seq="2000-0977" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html" adv="1">20001011 Mail File POST Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1807" adv="1">1807</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5358">mailfile-post-file-read(5358)</ref>
    </refs>
    <vuln_soft>
      <prod name="mail_file" vendor="oatmeal_studios">
        <vers num="1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0978" seq="2000-0978" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&amp;" shell metacharacter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0162.html" adv="1" patch="1">20001010 Big Brother Systems and Network Monitor vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1779" adv="1" patch="1">1779</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5719">bb4-netmon-execute-commands(5719)</ref>
    </refs>
    <vuln_soft>
      <prod name="big_brother_network_monitor" vendor="bb4">
        <vers num="1.5c2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0979" seq="2000-0979" published="2000-12-19" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97147777618139&amp;w=2">20001012 NSFOCUS SA2000-05: Microsoft Windows 9x NETBIOS password</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1780" adv="1" patch="1">1780</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-072">MS00-072</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5395">win9x-share-level-password(5395)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A996">oval:org.mitre.oval:def:996</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0980" seq="2000-0980" published="2000-12-19" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1781" adv="1" patch="1">1781</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-073">MS00-073</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5357">win-nmpi-packet-dos(5357)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0981" seq="2000-0981" published="2000-12-19" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0318.html">20001023 [CORE SDI ADVISORY] MySQL weak authentication</ref>
      <ref source="CONFIRM" url="http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security">http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5409">mysql-authentication(5409)</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="3.22"/>
        <vers num="3.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0982" seq="2000-0982" published="2000-12-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1793" adv="1" patch="1">1793</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-076">MS00-076</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5367">ie-cache-info(5367)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0983" seq="2000-0983" published="2000-12-19" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q273854">Q273854</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/140341">20001018 Denial of Service attack against computers running Microsoft NetMeeting</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1798" adv="1" patch="1">1798</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-077">MS00-077</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5368">netmeeting-desktop-sharing-dos(5368)</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0984" seq="2000-0984" published="2000-12-19" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/ioshttpserverquery-pub.shtml" adv="1" patch="1">20001025 Cisco IOS HTTP Server Query Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1838" adv="1" patch="1">1838</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5412">cisco-ios-query-dos(5412)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.0t"/>
        <vers num="12.0w5"/>
        <vers num="12.0xa"/>
        <vers num="12.0xe"/>
        <vers num="12.0xh"/>
        <vers num="12.0xj"/>
        <vers num="12.1aa"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1ec"/>
        <vers num="12.1t"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xl"/>
        <vers num="12.1xp"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0985" seq="2000-0985" published="2000-12-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a101200-2.txt" adv="1" patch="1">A101200-2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1789" adv="1" patch="1">1789</ref>
    </refs>
    <vuln_soft>
      <prod name="all-mail" vendor="nevis_systems">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0986" seq="2000-0986" published="2000-12-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0294.html" adv="1">20001020 [ Hackerslab bug_paper ] Linux ORACLE 8.1.5 vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5390">oracle-home-bo(5390)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0987" seq="2000-0987" published="2000-12-19" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/140340">20001018 vulnerability in Oracle Internet Directory in Oracle 8.1.6</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/140709" adv="1">20001020 In response to posting 10/18/2000 vulnerability in Oracle Internet Directory in Oracle 8.1.6</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5401">oracle-oidldap-bo(5401)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_directory" vendor="oracle">
        <vers num="2.0.6"/>
      </prod>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0988" seq="2000-0988" published="2000-12-19" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0238.html">20001013 WinU Backdoor passwords!!!!</ref>
      <ref source="CONFIRM" url="http://www.bardon.com/pwdcrack.htm">http://www.bardon.com/pwdcrack.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1801" adv="1" patch="1">1801</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5376">winu-backdoor(5376)</ref>
    </refs>
    <vuln_soft>
      <prod name="winu" vendor="bardon_data_systems">
        <vers num="5.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0989" seq="2000-0989" published="2000-12-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0293.html" adv="1">20001020 DoS in Intel corporation 'InBusiness eMail Station'</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5414">intel-email-username-bo(5414)</ref>
    </refs>
    <vuln_soft>
      <prod name="inbusiness_email_station" vendor="intel">
        <vers num="1.4.87"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0990" seq="2000-0990" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0258.html" adv="1">20001016 Authentication failure in cmd5checkpw 0.21</ref>
      <ref source="CONFIRM" url="http://members.elysium.pl/brush/cmd5checkpw/changes.html">http://members.elysium.pl/brush/cmd5checkpw/changes.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1809" adv="1" patch="1">1809</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5382">cmd5checkpw-qmail-bypass-authentication(5382)</ref>
    </refs>
    <vuln_soft>
      <prod name="cmd5checkpw" vendor="krzysztof_dabrowski">
        <vers num="0.20"/>
        <vers num="0.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0991" seq="2000-0991" published="2000-12-19" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1815" adv="1" patch="1">1815</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-079">MS00-079</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5387">win-hyperterminal-telnet-bo(5387)</ref>
    </refs>
    <vuln_soft>
      <prod name="hyperterminal" vendor="hilgraeve">
        <vers num="6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0992" seq="2000-0992" published="2000-12-19" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0359.html" adv="1">20000930 scp file transfer hole</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:057">MDKSA-2000:057</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1742" adv="1" patch="1">1742</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5312">scp-overwrite-files(5312)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2"/>
        <vers num="1.2.3"/>
      </prod>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.14"/>
        <vers num="1.2.15"/>
        <vers num="1.2.16"/>
        <vers num="1.2.17"/>
        <vers num="1.2.18"/>
        <vers num="1.2.19"/>
        <vers num="1.2.20"/>
        <vers num="1.2.21"/>
        <vers num="1.2.22"/>
        <vers num="1.2.23"/>
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0993" seq="2000-0993" published="2000-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:58.chpass.asc">FreeBSD-SA-00:58</ref>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-015.txt.asc">NetBSD-SA2000-015</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata27.html#pw_error">20001003 A format string vulnerability exists in the pw_error(3) function.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1744" adv="1" patch="1">1744</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5339">bsd-libutil-format(5339)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="4.0"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0994" seq="2000-0994" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1746" adv="1">1746</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5338">bsd-fstat-format(5338)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0995" seq="2000-0995" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5635">bsd-yp-passwd-format(5635)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0996" seq="2000-0996" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5636">bsd-su-format(5636)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0997" seq="2000-0997" published="2000-12-19" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1752" adv="1" patch="1">1752</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5337">bsd-eeprom-format(5337)</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0998" seq="2000-0998" published="2000-12-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:62.top.v1.1.asc" adv="1" patch="1">FreeBSD-SA-00:62</ref>
      <ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1895" adv="1" patch="1">1895</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5" edition="stable"/>
        <vers num="3.5.1" edition="release"/>
        <vers num="3.5.1" edition="stable"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-0999" seq="2000-0999" published="2000-12-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch" adv="1" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1000" seq="2000-1000" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in AOL Instant Messenger (AIM) 4.1.2010 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by transferring a file whose name includes format characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/137374" adv="1">20001003 AOL Instant Messenger DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1747" adv="1">1747</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5314">aim-file-transfer-dos(5314)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.1.2010"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1001" seq="2000-1001" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the "price" hidden form variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97240616129614&amp;w=2">20001024 Price modification in Element InstantShop</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5402">instantshop-modify-price(5402)</ref>
    </refs>
    <vuln_soft>
      <prod name="element_instantshop" vendor="element_n.v">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1002" seq="2000-1002" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/139523" adv="1">20001012 Re: Netscape Messaging server 4.15 poor error strings</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1792" adv="1">1792</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5363">communigate-email-verify(5363)</ref>
    </refs>
    <vuln_soft>
      <prod name="communigate_pro" vendor="stalker">
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1003" seq="2000-1003" published="2000-12-11" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/139511">20001012 NSFOCUS SA2000-04: Microsoft Win9x client driver type comparing vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1794" adv="1">1794</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5370">win-netbios-driver-type-dos(5370)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1004" seq="2000-1004" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5336">bsd-photurisd-format(5336)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1005" seq="2000-1005" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/138495">20001009 Security Advisory : eXtropia WebStore (web_store.cgi) Directory Traversal Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1774" adv="1" patch="1">1774</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5347">extropia-webstore-fileread(5347)</ref>
    </refs>
    <vuln_soft>
      <prod name="extropia_webstore" vendor="extropia">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1006" seq="2000-1006" published="2000-12-11" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1869" adv="1" patch="1">1869</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-082">MS00-082</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5448">ms-exchange-mime-dos(5448)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1007" seq="2000-1007" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0048.html" adv="1" patch="1">20001025 I-gear 3.5.x for Microsoft Proxy logging vulnerability + temporary fix.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5791">igear-invalid-log(5791)</ref>
    </refs>
    <vuln_soft>
      <prod name="i-gear" vendor="symantec">
        <vers num="3.5"/>
        <vers num="3.5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1008" seq="2000-1008" published="2000-12-11" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a092600-1.txt" adv="1" patch="1">A092600-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1715" adv="1" patch="1">1715</ref>
    </refs>
    <vuln_soft>
      <prod name="palm_os" vendor="palm">
        <vers num="3.5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1009" seq="2000-1009" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0438.html">20001030 Redhat 6.2 dump command executes external program with suid priviledge.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1871" adv="1" patch="1">1871</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5437">linux-dump-execute-code(5437)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1010" seq="2000-1010" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/137890" adv="1">20001006 talkd [WAS: Re: OpenBSD Security Advisory]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1764" adv="1" patch="1">1764</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5344">linux-talkd-overwrite-root(5344)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":alpha"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="5.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1011" seq="2000-1011" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc" adv="1" patch="1">FreeBSD-SA-00:53</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5638">freebsd-catopen-bo(5638)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1012" seq="2000-1012" published="2000-12-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc" adv="1" patch="1">FreeBSD-SA-00:53</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1013" seq="2000-1013" published="2000-12-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc" adv="1" patch="1">FreeBSD-SA-00:53</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1014" seq="2000-1014" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0325.html">20000927 Unixware SCOhelp http server format string vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1717" adv="1" patch="1">1717</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5291">unixware-scohelp-format(5291)</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="sco">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1015" seq="2000-1015" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0366.html" adv="1" patch="1">20000929 Default admin password with Slashcode.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1731" adv="1" patch="1">1731</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5306">slashcode-default-admin-passwords(5306)</ref>
    </refs>
    <vuln_soft>
      <prod name="slashcode" vendor="open_source_development_network">
        <vers num="1.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1016" seq="2000-1016" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84360">20000921 httpd.conf in Suse 6.4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1707" adv="1" patch="1">1707</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5276">suse-installed-packages-exposed(5276)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1017" seq="2000-1017" published="2000-12-11" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0007.html">20001002 DST2K0039: Webteachers Webdata: Importing files lower than web ro ot possible in to database</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0032.html" adv="1" patch="1">20001003 Update to DST2K0039: Webteachers Webdata: Importing files lower t han web root possible in to database</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1732" adv="1" patch="1">1732</ref>
    </refs>
    <vuln_soft>
      <prod name="webdata" vendor="webteacher">
        <vers num="2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1018" seq="2000-1018" published="2000-12-11" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred from properly replacing the file's data and allows local users to recover the file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97119799515246&amp;w=2">20001010 Shred 1.0 Bug Report</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97131166004145&amp;w=2">20001011 Shred v1.0 Fix</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1788" adv="1" patch="1">1788</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5722">shred-recover-files(5722)</ref>
    </refs>
    <vuln_soft>
      <prod name="shred" vendor="mendel_cooper">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1019" seq="2000-1019" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97301487015664&amp;w=2">20001030 Ultraseek 3.1.x Remote DoS Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1866" adv="1" patch="1">1866</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5439">ultraseek-malformed-url-dos(5439)</ref>
    </refs>
    <vuln_soft>
      <prod name="search_software" vendor="inktomi">
        <vers num="3.0"/>
        <vers num="3.1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1020" seq="2000-1020" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96925269716274&amp;w=2">20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1689" adv="1" patch="1">1689</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5250">mdaemon-url-dos(5250)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1021" seq="2000-1021" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96925269716274&amp;w=2">20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1689" adv="1" patch="1">1689</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5250">mdaemon-url-dos(5250)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="3.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1022" seq="2000-1022" published="2000-12-11" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0222.html">20000919 Cisco PIX Firewall (smtp content filtering hack)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0241.html">20000920 Re: Cisco PIX Firewall (smtp content filtering hack) - Version 4.2(1) not exploitable</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/PIXfirewallSMTPfilter-pub.shtml">20001005 Cisco Secure PIX Firewall Mailguard Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1698" adv="1" patch="1">1698</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5277">cisco-pix-smtp-filtering(5277)</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="4.2(1)"/>
        <vers num="4.2(2)"/>
        <vers num="4.2(5)"/>
        <vers num="4.3"/>
        <vers num="4.4(4)"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1023" seq="2000-1023" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84766">20000924 Major Vulnerability in Alabanza Control Panel</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1710" adv="1" patch="1">1710</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5284">alabanza-unauthorized-access(5284)</ref>
    </refs>
    <vuln_soft>
      <prod name="control_panel" vendor="alabanza">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1024" seq="2000-1024" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97306581513537&amp;w=2">20001101 Unify eWave ServletExec upload</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1876" adv="1" patch="1">1876</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5450">ewave-servletexec-file-upload(5450)</ref>
    </refs>
    <vuln_soft>
      <prod name="ewave_servletexec" vendor="unify">
        <vers num="3.0c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1025" seq="2000-1025" published="2000-12-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97295224226042&amp;w=2">20001030 Unify eWave ServletExec DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1868" adv="1" patch="1">1868</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5435">ewave-servletexec-dos(5435)</ref>
    </refs>
    <vuln_soft>
      <prod name="ewave_servletexec" vendor="unify">
        <vers num="3.0c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1026" seq="2000-1026" published="2000-12-11" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:61.tcpdump.v1.1.asc">FreeBSD-SA-00:61</ref>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0681.html">SuSE-SA:2000:46</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1870" adv="1" patch="1">1870</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5480">tcpdump-afs-packet-overflow(5480)</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.4"/>
        <vers num="3.4a6"/>
        <vers num="3.5"/>
        <vers num="3.5_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1027" seq="2000-1027" published="2000-12-11" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97059440000367&amp;w=2">20001003 Cisco PIX Firewall allow external users to discover internal IPs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1877" adv="1">1877</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5646">cisco-pix-reveal-address(5646)</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall_software" vendor="cisco">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1028" seq="2000-1028" published="2000-12-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/142792">20001102 HPUX cu -l option buffer overflow vulnerabilit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1886" adv="1" patch="1">1886</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5460">hp-cu-bo(5460)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="9.00"/>
        <vers num="9.01"/>
        <vers num="9.04"/>
        <vers num="9.05"/>
        <vers num="9.06"/>
        <vers num="9.07"/>
        <vers num="9.08"/>
        <vers num="9.09"/>
        <vers num="9.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1029" seq="2000-1029" published="2000-12-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141660" adv="1">20001027 old version of host command vulnearbility</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1887" adv="1" patch="1">1887</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5462">isc-bind-axfr-bo(5462)</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1030" seq="2000-1030" published="2000-12-11" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CS&amp;T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/142672">20001031 Re: Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1888" adv="1">1888</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5529">corporatetime-brute-force(5529)</ref>
    </refs>
    <vuln_soft>
      <prod name="corporatetime_for_the_web" vendor="csandt">
        <vers num="2.1.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1031" seq="2000-1031" published="2000-12-11" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html">20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification</ref>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0034.html" adv="1" patch="1">HPSBUX0011-128</ref>
      <ref source="HP" url="http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&amp;dt=11">SSRT2275</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/320067">VU#320067</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/290115">20020902 Happy Labor Day from Snosoft</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/75188">20000810 Re: Possible vulnerability in HPUX ( Add vulnerability List )</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1889" adv="1" patch="1">1889</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5461">hp-dtterm(5461)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.4"/>
      </prod>
      <prod name="tru64" vendor="hp">
        <vers num="4.0f" edition="pk8"/>
        <vers num="4.0g" edition="pk4"/>
        <vers num="5.0a"/>
        <vers num="5.1"/>
        <vers num="5.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1032" seq="2000-1032" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/142808" adv="1">20001101 Re: Samba 2.0.7 SWAT vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1890" adv="1" patch="1">1890</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5816">fw1-login-response(5816)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1033" seq="2000-1033" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141905">20001029 Brute Forcing FTP Servers with enabled anti-hammering (anti brute-force) modus</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1860" adv="1">1860</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5436">ftp-servu-brute-force(5436)</ref>
    </refs>
    <vuln_soft>
      <prod name="serv-u" vendor="cat_soft">
        <vers num="2.5x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1034" seq="2000-1034" published="2000-12-11" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97349782305448&amp;w=2">20001106 System Monitor ActiveX Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1899" adv="1" patch="1">1899</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-085">MS00-085</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5467">system-monitor-activex-bo(5467)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1035" seq="2000-1035" published="2000-12-11" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96879389027478&amp;w=2">20000912 TYPSoft FTP Server remote DoS Problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1690" adv="1">1690</ref>
      <ref source="MISC" url="http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt">http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="typsoft" vendor="typsoft">
        <vers num="0.7x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1036" seq="2000-1036" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0252.html" adv="1" patch="1">20000920 Extent RBS directory Transversal.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1704" adv="1" patch="1">1704</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5275">rbs-isp-directory-traversal(5275)</ref>
    </refs>
    <vuln_soft>
      <prod name="rbs_isp" vendor="extent_technologies">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1037" seq="2000-1037" published="2000-12-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/76389" adv="1">20000815 Firewall-1 session agent 3.0 -> 4.1, dictionnary and brute force attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1662" adv="1">1662</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1038" seq="2000-1038" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument" adv="1" patch="1">http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=SA90544&amp;apar=only">SA90544</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5266">as400-firewall-dos(5266)</ref>
    </refs>
    <vuln_soft>
      <prod name="as400_firewall" vendor="ibm">
        <vers num="r440"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1039" seq="2000-1039" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities.  NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0105.html">20001204 NAPTHA Advisory Updated - BindView RAZOR</ref>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_NAPTHA.html">20001130 The NAPTHA DoS vulnerabilities</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2000-21.html" adv="1" patch="1">CA-2000-21</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2022" adv="1" patch="1">2022</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-091">MS00-091</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1040" seq="2000-1040" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0356.html">20001025 Immunix OS Security Update for ypbind package</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html">20001030 Trustix Security Advisory - ping gnupg ypbind</ref>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html">SuSE-SA:2000:042</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt">CSSA-2000-039.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001014">20001014 nis: local exploit</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MDKSA-2000:064</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-086.html">RHSA-2000:086</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1820" adv="1" patch="1">1820</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5394">ypbind-printf-format-string(5394)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1041" seq="2000-1041" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ypbind 3.3 possibly allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html" adv="1" patch="1">SuSE-SA:2000:042</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt" adv="1" patch="1">CSSA-2000-039.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1" adv="1" patch="1">MDKSA-2000:064</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5759">ypbind-remote-bo(5759)</ref>
    </refs>
    <vuln_soft>
      <prod name="ypbind" vendor="swen_thuemmler">
        <vers num="3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1042" seq="2000-1042" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1" adv="1" patch="1">MDKSA-2000:064</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5730">linux-ypserv-bo(5730)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1043" seq="2000-1043" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1" adv="1" patch="1">MDKSA-2000:064</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5731">linux-ypserv-format-string(5731)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1044" seq="2000-1044" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html" adv="1" patch="1">SuSE-SA:2000:042</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1820" adv="1" patch="1">1820</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5394">ypbind-printf-format-string(5394)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1045" seq="2000-1045" published="2000-12-11" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-066-1.php3" adv="1" patch="1">MDKSA-2000-066</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-024.html" adv="1" patch="1">RHSA-2000:024</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1863" adv="1" patch="1">1863</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5449">nssldap-nscd-dos(5449)</ref>
    </refs>
    <vuln_soft>
      <prod name="nss_ldap" vendor="padl_software">
        <vers num="build_85"/>
        <vers num="build_105"/>
        <vers num="build_113"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1046" seq="2000-1046" published="2000-12-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) "RCPT TO," (2) "SAML FROM," or (3) "SOML FROM" commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0093.html" adv="1" patch="1">20000911 Advisory Code: VIGILANTE-2000011 Lotus Domino ESMTP Service Buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="domino" vendor="lotus">
        <vers num="5.0.2a"/>
        <vers num="5.0.2c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1047" seq="2000-1047" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyword in the "MAIL FROM" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143071" adv="1" patch="1">20001103 [SAFER] Buffer overflow in Lotus Domino SMTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1905" adv="1" patch="1">1905</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5488">lotus-domino-smtp-envid(5488)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_enterprise_server" vendor="lotus">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.2b"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
      </prod>
      <prod name="domino_mail_server" vendor="lotus">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.2b"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1048" seq="2000-1048" published="2000-12-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0245.html" adv="1">20001016 Wingate 4.1 Beta A vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5373">wingate-view-files(5373)</ref>
    </refs>
    <vuln_soft>
      <prod name="wingate" vendor="qbik">
        <vers num="2.1"/>
        <vers num="3.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1_beta_a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1049" seq="2000-1049" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97310314724964&amp;w=2">20001101 Allaire's JRUN DoS</ref>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=18085&amp;Method=Full" adv="1" patch="1">ASB00-030</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5452">allaire-jrun-servlet-dos(5452)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="3.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1050" seq="2000-1050" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request (aka the "extra leading slash").</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97236316510117&amp;w=2">20001023 Allaire's JRUN Unauthenticated Access to WEB-INF directory</ref>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=17966&amp;Method=Full" adv="1" patch="1">ASB00-027</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5407">allaire-jrun-webinf-access(5407)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="3.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1051" seq="2000-1051" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97236692714978&amp;w=2">20001023 Allaire JRUN 2.3 Arbitrary File Retrieval</ref>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=17968&amp;Method=Full" adv="1" patch="1">ASB00-028</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5405">allaire-jrun-ssifilter-url(5405)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1052" seq="2000-1052" published="2000-12-11" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97236692714978&amp;w=2">20001023 Allaire JRUN 2.3 Arbitrary File Retrieval</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1053" seq="2000-1053" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97236125107957&amp;w=2">20001023 Allaire JRUN 2.3 Remote command execution</ref>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=17969&amp;Method=Full" adv="1" patch="1">ASB00-029</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5406">allaire-jrun-jsp-execute(5406)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1054" seq="2000-1054" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml" adv="1" patch="1">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1705" adv="1" patch="1">1705</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5272">ciscosecure-csadmin-bo(5272)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_access_control_server" vendor="cisco">
        <vers num="2.1" edition=":windows_nt"/>
        <vers num="2.3(3)" edition=":windows_nt"/>
        <vers num="2.4(2)" edition=":windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1055" seq="2000-1055" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml" adv="1" patch="1">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1706" adv="1" patch="1">1706</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5273">ciscosecure-tacacs-dos(5273)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_access_control_server" vendor="cisco">
        <vers num="2.1" edition=":windows_nt"/>
        <vers num="2.3(3)" edition=":windows_nt"/>
        <vers num="2.4(2)" edition=":windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1056" seq="2000-1056" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml" adv="1" patch="1">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1708" adv="1" patch="1">1708</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5274">ciscosecure-ldap-bypass-authentication(5274)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_access_control_server" vendor="cisco">
        <vers num="2.1" edition=":windows_nt"/>
        <vers num="2.3(3)" edition=":windows_nt"/>
        <vers num="2.4(2)" edition=":windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1057" seq="2000-1057" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerabilities in database configuration scripts in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows local users to gain privileges, possibly via insecure permissions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0140.html" adv="1" patch="1">HPSBUX0009-120</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1682" adv="1" patch="1">1682</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5229">hp-openview-nnm-scripts(5229)</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="4.11" edition=":hp_ux"/>
        <vers num="4.11" edition=":solaris"/>
        <vers num="5.01" edition=":hp_ux"/>
        <vers num="5.01" edition=":solaris"/>
        <vers num="6.1" edition=":hp_ux_10.x"/>
        <vers num="6.1" edition=":hp_ux_11.x"/>
        <vers num="6.1" edition=":solaris"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1058" seq="2000-1058" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the "Java SNMP MIB Browser Object ID parsing problem."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0274.html" adv="1" patch="1">HPSBUX0009-121</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97004856403173&amp;w=2">20000926 DST2K0014: BufferOverrun in HP Openview Network Node Manager v6.1 (Round2)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5282">openview-nmm-snmp-bo(5282)</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="4.11"/>
        <vers num="5.01"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1059" seq="2000-1059" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-052.php3">MDKSA-2000:052</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/136495">20000929 Mandrake 7.1 bypasses Xauthority X session security.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1735" adv="1" patch="1">1735</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5305">xinitrc-bypass-xauthority(5305)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1060" seq="2000-1060" published="2000-12-11" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0022.html">20001002 Local vulnerability in XFCE 3.5.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1736" adv="1" patch="1">1736</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5305">xinitrc-bypass-xauthority(5305)</ref>
    </refs>
    <vuln_soft>
      <prod name="xfce" vendor="xfree86_project">
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1061" seq="2000-1061" published="2000-12-11" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the "Microsoft VM ActiveX Component" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-075">MS00-075</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5127">java-vm-applet(5127)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.x"/>
        <vers num="5.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1062" seq="2000-1062" published="2000-12-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the FTP service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97119729613778&amp;w=2">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1775" adv="1" patch="1">1775</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5353">hp-jetdirect-firmware-dos(5353)</ref>
    </refs>
    <vuln_soft>
      <prod name="jetdirect" vendor="hp">
        <vers num="x.08.04"/>
        <vers num="x.08.05"/>
        <vers num="x.08.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1063" seq="2000-1063" published="2000-12-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97119729613778&amp;w=2">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1775" adv="1" patch="1">1775</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5353">hp-jetdirect-firmware-dos(5353)</ref>
    </refs>
    <vuln_soft>
      <prod name="jetdirect" vendor="hp">
        <vers num="x.08.04"/>
        <vers num="x.08.05"/>
        <vers num="x.08.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1064" seq="2000-1064" published="2000-12-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97119729613778&amp;w=2">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1775" adv="1" patch="1">1775</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5353">hp-jetdirect-firmware-dos(5353)</ref>
    </refs>
    <vuln_soft>
      <prod name="jetdirect" vendor="hp">
        <vers num="x.08.04"/>
        <vers num="x.08.05"/>
        <vers num="x.08.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1065" seq="2000-1065" published="2000-12-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97119729613778&amp;w=2">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1775" adv="1" patch="1">1775</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5354">hp-jetdirect-ip-implementation(5354)</ref>
    </refs>
    <vuln_soft>
      <prod name="jetdirect" vendor="hp">
        <vers num="x.08.04"/>
        <vers num="x.08.05"/>
        <vers num="x.08.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1066" seq="2000-1066" published="2000-12-11" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:63.getnameinfo.asc">FreeBSD-SA-00:63</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1894" adv="1" patch="1">1894</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5454">getnameinfo-dos(5454)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0" edition="alpha"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="release"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1068" seq="2000-1068" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97236719315352&amp;w=2">20001023 Re: Poll It v2.0 cgi (again)</ref>
      <ref source="CONFIRM" url="http://www.cgi-world.com/pollit.html">http://www.cgi-world.com/pollit.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5792">pollit-polloptions-execute-commands(5792)</ref>
    </refs>
    <vuln_soft>
      <prod name="poll_it" vendor="cgi-world">
        <vers num="2.0"/>
      </prod>
      <prod name="poll_it_pro" vendor="cgi-world">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1069" seq="2000-1069" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97236719315352&amp;w=2">20001023 Re: Poll It v2.0 cgi (again)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5419">pollit-admin-password-var(5419)</ref>
    </refs>
    <vuln_soft>
      <prod name="poll_it" vendor="cgi-world">
        <vers num="2.0"/>
        <vers num="2.01"/>
      </prod>
      <prod name="poll_it_pro" vendor="cgi-world">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1070" seq="2000-1070" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97236719315352&amp;w=2">20001023 Re: Poll It v2.0 cgi (again)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5794">pollit-webroot-gain-access(5794)</ref>
    </refs>
    <vuln_soft>
      <prod name="poll_it" vendor="cgi-world">
        <vers num="2.0"/>
        <vers num="2.01"/>
      </prod>
      <prod name="poll_it_pro" vendor="cgi-world">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1071" seq="2000-1071" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" adv="1" patch="1">A100900-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1767">1767</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5752">ical-xhost-gain-privileges(5752)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_ical" vendor="netscape">
        <vers num="2.1" edition="patch2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1072" seq="2000-1072" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" adv="1" patch="1">A100900-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1768" adv="1" patch="1">1768</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5756">ical-iplncal-gain-access(5756)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_ical" vendor="netscape">
        <vers num="2.1" edition="patch2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1073" seq="2000-1073" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" adv="1" patch="1">A100900-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1769" adv="1" patch="1">1769</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5757">ical-csstart-gain-access(5757)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_ical" vendor="netscape">
        <vers num="2.1" edition="patch2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1074" seq="2000-1074" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt" adv="1" patch="1">A100900-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1769" adv="1" patch="1">1769</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5757">ical-csstart-gain-access(5757)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_ical" vendor="netscape">
        <vers num="2.1" edition="patch2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1075" seq="2000-1075" published="2000-12-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html">20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug</ref>
      <ref source="CONFIRM" url="http://www.iplanet.com/downloads/patches/0122.html">http://www.iplanet.com/downloads/patches/0122.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1839" adv="1" patch="1">1839</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5421">iplanet-netscape-directory-traversal(5421)</ref>
    </refs>
    <vuln_soft>
      <prod name="directory_server" vendor="netscape">
        <vers num="4.12"/>
      </prod>
      <prod name="iplanet_certificate_management_system" vendor="sun">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1076" seq="2000-1076" published="2000-12-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html">20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5422">iplanet-netscape-plaintext-password(5422)</ref>
    </refs>
    <vuln_soft>
      <prod name="directory_server" vendor="netscape">
        <vers num="4.12"/>
      </prod>
      <prod name="iplanet_certificate_management_system" vendor="sun">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1077" seq="2000-1077" published="2000-12-11" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141435" adv="1" patch="1">20001026 Buffer overflow in iPlanet Web Server 4 server side SHTML parsing module</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5446">iplanet-web-server-shtml-bo(5446)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="iplanet">
        <vers num="4.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1078" seq="2000-1078" published="2000-12-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/138332" adv="1">20001007 ICQ WebFront HTTPd DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5332">icq-webfront-url-dos(5332)</ref>
    </refs>
    <vuln_soft>
      <prod name="icq_web_front" vendor="mirabilis">
        <vers num="windows_9x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1079" seq="2000-1079" published="2000-08-29" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0116.html">20000829 Re: [COVERT-2000-10] Windows NetBIOS Unsolicited Cache Corruption</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/045.asp">20000829 Windows NetBIOS Unsolicited Cache Corruption</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1620" adv="1" patch="1">1620</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5168">win-netbios-corrupt-cache(5168)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1079">oval:org.mitre.oval:def:1079</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1080" seq="2000-1080" published="2000-11-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97318797630246&amp;w=2">20001102 dos on quake1 servers</ref>
      <ref source="CONFIRM" url="http://proquake.ai.mit.edu/">http://proquake.ai.mit.edu/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1900" adv="1" patch="1">1900</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5527">quake-empty-udp-dos(5527)</ref>
    </refs>
    <vuln_soft>
      <prod name="quake" vendor="id_software">
        <vers num="1.9"/>
      </prod>
      <prod name="proquake" vendor="j._p._grossman">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1081" seq="2000-1081" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2030" adv="1" patch="1">2030</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A231">oval:org.mitre.oval:def:231</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1082" seq="2000-1082" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2031" adv="1" patch="1">2031</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1083" seq="2000-1083" published="2001-01-09" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2038" adv="1" patch="1">2038</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1084" seq="2000-1084" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2039" adv="1" patch="1">2039</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1085" seq="2000-1085" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2040" adv="1" patch="1">2040</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1086" seq="2000-1086" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2041" adv="1" patch="1">2041</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1087" seq="2000-1087" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2042" adv="1" patch="1">2042</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1088" seq="2000-1088" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://marc.info/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2043" adv="1" patch="1">2043</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-092">MS00-092</ref>
    </refs>
    <vuln_soft>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1089" seq="2000-1089" published="2001-01-09" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2048" adv="1" patch="1">2048</ref>
      <ref source="ATSTAKE" url="http://www.stake.com/research/advisories/2000/a120400-1.txt" adv="1" patch="1">A120400-1</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-094">MS00-094</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5623">phone-book-service-bo(5623)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1090" seq="2000-1090" published="2001-02-12" modified="2018-01-11" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.nsfocus.com/english/homepage/sa_08.htm">http://www.nsfocus.com/english/homepage/sa_08.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2100" adv="1">2100</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5729" adv="1">microsoft-iis-file-disclosure(5729)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0" edition=":~~far_east~~~"/>
        <vers num="5.0" edition=":~~far_east~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1092" seq="2000-1092" published="2001-01-09" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97676270729984&amp;w=2">20001213 NSFOCUS SA2000-09 : AHG EZshopper Loadpage.cgi File List</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2109" adv="1">2109</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5740">ezshopper-cgi-file-disclosure(5740)</ref>
    </refs>
    <vuln_soft>
      <prod name="ezshopper" vendor="alex_heiphetz_group">
        <vers num="2.0"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1093" seq="2000-1093" published="2001-01-09" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a121200-1.txt" adv="1" patch="1">A121200-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5732">aim-remote-bo(5732)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="2.0_n"/>
        <vers num="2.5.1366"/>
        <vers num="2.5.1598"/>
        <vers num="3.0.1470"/>
        <vers num="3.0_n"/>
        <vers num="3.5.1635"/>
        <vers num="3.5.1670"/>
        <vers num="3.5.1808"/>
        <vers num="3.5.1856"/>
        <vers num="4.0"/>
        <vers num="4.1.2010"/>
        <vers num="4.2.1193"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1094" seq="2000-1094" published="2001-01-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a long "src" argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97668265628917&amp;w=2">20001213 Administrivia &amp; AOL IM Advisory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97683774417132&amp;w=2">20001214 Re: AIM &amp; @stake's advisory</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a121200-1.txt" adv="1" patch="1">A121200-1</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="2.0_n"/>
        <vers num="2.5.1366"/>
        <vers num="2.5.1598"/>
        <vers num="3.0.1470"/>
        <vers num="3.0_n"/>
        <vers num="3.5.1635"/>
        <vers num="3.5.1670"/>
        <vers num="3.5.1808"/>
        <vers num="3.5.1856"/>
        <vers num="4.0"/>
        <vers num="4.1.2010"/>
        <vers num="4.2.1193"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1095" seq="2000-1095" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0179.html">20001112 RedHat 7.0 (and SuSE): modutils + netkit = root compromise. (fwd)</ref>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0596.html">SuSE-SA:2000:44</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000340">CLSA-2000:340</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001120">20001120 modutils: local exploit</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-071-1.php3?dis=7.1">MDKSA-2000:071</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-108.html" adv="1" patch="1">RHSA-2000:108</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1936" adv="1" patch="1">1936</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5516">linux-modprobe-execute-code(5516)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="5.1"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1096" seq="2000-1096" published="2001-01-09" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0237.html">20001116 vixie cron...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1960" adv="1" patch="1">1960</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5543">vixie-cron-execute-commands(5543)</ref>
    </refs>
    <vuln_soft>
      <prod name="vixie_cron" vendor="paul_vixie">
        <vers num="3.0_pl1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1097" seq="2000-1097" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0406.html" adv="1">20001129 DoS in Sonicwall SOHO firewall</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html">20001201 FW: SonicWALL SOHO Vulnerability (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2013" adv="1" patch="1">2013</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5596">sonicwall-soho-dos(5596)</ref>
    </refs>
    <vuln_soft>
      <prod name="soho_firewall" vendor="sonicwall">
        <vers num="4.0.0"/>
        <vers num="5.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1098" seq="2000-1098" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html" patch="1">20001201 FW: SonicWALL SOHO Vulnerability (fwd)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0439.html" adv="1">20001201 Re: DoS in Sonicwall SOHO firewall</ref>
    </refs>
    <vuln_soft>
      <prod name="soho_firewall" vendor="sonicwall">
        <vers num="4.0.0"/>
        <vers num="5.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1099" seq="2000-1099" published="2001-01-09" modified="2018-09-20" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/199&amp;type=0&amp;nav=sec.sba">00199</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0011-132">HPSBUX0011-132</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5605" adv="1">jdk-untrusted-java-class(5605)</ref>
    </refs>
    <vuln_soft>
      <prod name="jdk" vendor="sun">
        <vers num="1.2.1" prev="1" edition="update3"/>
        <vers num="1.2.2" edition="update4"/>
        <vers num="1.2.2" edition="update5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1100" seq="2000-1100" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0433.html" adv="1" patch="1">20001130 PostACI Webmail Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2029" adv="1" patch="1">2029</ref>
    </refs>
    <vuln_soft>
      <prod name="postaci_webmail" vendor="trlinux">
        <vers num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1101" seq="2000-1101" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0386.html" adv="1" patch="1">20001127 Vulnerability in Winsock FTPD 2.41/3.00 (Pro)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5608.php">wftpd-dir-traverse(5608)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2005" adv="1" patch="1">2005</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.41_rc14" edition=":pro"/>
        <vers num="3.0" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1102" seq="2000-1102" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/147115" adv="1">20001126 Vulnerablity in PTlink3.5.3ircd + PTlink.Services.1.8.1...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2008" adv="1" patch="1">2008</ref>
    </refs>
    <vuln_soft>
      <prod name="ptlink_irc_services" vendor="ptlink">
        <vers num="1.8.1"/>
      </prod>
      <prod name="ptlink_ircd" vendor="ptlink">
        <vers num="3.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1103" seq="2000-1103" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/147120" adv="1">20001127 BSDi 3.0/4.0 rcvtty gid=tty exploit... (mh package)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2009" adv="1">2009</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1104" seq="2000-1104" published="2001-01-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.  The client then executes those scripts in the same context as the trusted site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-060">MS00-060</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1105" seq="2000-1105" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0074.html" adv="1" patch="1">20001110 IE 5.x Win2000 Indexing service vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/144270">20001110 IE 5.x Win2000 Indexing service vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1933" adv="1" patch="1">1933</ref>
    </refs>
    <vuln_soft>
      <prod name="indexing_service" vendor="microsoft">
        <vers num="" edition=":windows_2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1106" seq="2000-1106" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0016.html">20001201 Responding to BugTraq ID 2014 - "Trend Micro InterScan VirusWall Shared Directory Vulnerability"</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/147563" adv="1" patch="1">20001128 TrendMicro InterScan VirusWall shared folder problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2014" adv="1" patch="1">2014</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5606">interscan-viruswall-unauth-access(5606)</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1107" seq="2000-1107" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0387.html" adv="1" patch="1">20001128 SuSE Linux 6.x 7.0 Ident buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2015" adv="1" patch="1">2015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5590">linux-ident-bo(5590)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1108" seq="2000-1108" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0192.html">20001113 Problems with cons.saver</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001125" adv="1" patch="1">20001125 mc: local DoS</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-078.php3">MDKSA-2000:078</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1945" adv="1" patch="1">1945</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5519">midnight-commander-conssaver-symlink(5519)</ref>
    </refs>
    <vuln_soft>
      <prod name="midnight_commander" vendor="midnight_commander">
        <vers num="4.5.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1109" seq="2000-1109" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0373.html" adv="1">20001127 Midnight Commander</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-036">DSA-036</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_011_mc.html">SuSE-SA:2001:11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2016" adv="1">2016</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5929">midnight-commander-elevate-privileges(5929)</ref>
    </refs>
    <vuln_soft>
      <prod name="midnight_commander" vendor="midnight_commander">
        <vers num="4.5.40"/>
        <vers num="4.5.41"/>
        <vers num="4.5.42"/>
        <vers num="4.5.43"/>
        <vers num="4.5.44"/>
        <vers num="4.5.45"/>
        <vers num="4.5.46"/>
        <vers num="4.5.47"/>
        <vers num="4.5.48"/>
        <vers num="4.5.49"/>
        <vers num="4.5.50"/>
        <vers num="4.5.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1110" seq="2000-1110" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0384.html" adv="1">20001128 IBM Net.Data Local Path Disclosure Vulnerability?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2017" adv="1">2017</ref>
    </refs>
    <vuln_soft>
      <prod name="net.data" vendor="ibm">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1111" seq="2000-1111" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/147914" adv="1">20001129 Windows 2000 Telnet Service DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2018" adv="1">2018</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5598">win2k-telnet-dos(5598)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1112" seq="2000-1112" published="2001-01-09" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1976" adv="1" patch="1">1976</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-090">MS00-090</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5575">mediaplayer-wms-script-exe(5575)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="6.4"/>
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1113" seq="2000-1113" published="2001-01-09" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the ".ASX Buffer Overrun" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a112300-1.txt">A112300-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1980" adv="1" patch="1">1980</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-090">MS00-090</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5574">mediaplayer-asx-bo(5574)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="6.4"/>
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1114" seq="2000-1114" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0285.html" adv="1" patch="1">20001121 Disclosure of JSP source code with ServletExec AS v3.0c + web ins tance</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1970" adv="1" patch="1">1970</ref>
    </refs>
    <vuln_soft>
      <prod name="ewave_servletexec" vendor="unify">
        <vers num="3.0"/>
        <vers num="3.0c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1115" seq="2000-1115" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0299.html" adv="1" patch="1">20001122 602Pro Lan Suite Web Admin Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1979" adv="1" patch="1">1979</ref>
      <ref source="CONFIRM" url="http://www.software602.com/products/ls/support/newbuild.html">http://www.software602.com/products/ls/support/newbuild.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5583">software602-lan-suite-bo(5583)</ref>
    </refs>
    <vuln_soft>
      <prod name="602pro_lan_suite" vendor="software602">
        <vers num="2000a_2000.0.1.32" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1116" seq="2000-1116" published="2001-01-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0041.html">20001018 TransSoft's Broker FTP Server 3.x &amp; 4.x Remote DoS attack Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5388">broker-ftp-username-dos(5388)</ref>
    </refs>
    <vuln_soft>
      <prod name="broker_ftp_server" vendor="transsoft">
        <vers num="3.0"/>
        <vers num="3.0_build_1"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1117" seq="2000-1117" published="2001-01-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0341.html">20001124 Security Hole in ECL Feature of Java VM Embedded in Lotus Notes Client R5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1994" adv="1">1994</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_notes" vendor="ibm">
        <vers num="r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1118" seq="2000-1118" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0369.html" adv="1" patch="1">20001127 24Link Webserver</ref>
    </refs>
    <vuln_soft>
      <prod name="24link" vendor="24link">
        <vers num="1.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1119" seq="2000-1119" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2032" adv="1" patch="1">2032</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08812&amp;apar=only">IY08812</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY10721&amp;apar=only">IY10721</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5621">aix-setsenv-bo(5621)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1120" seq="2000-1120" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2033" adv="1" patch="1">2033</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only">IY08143</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only">IY08287</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5620">aix-digest-bo(5620)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1121" seq="2000-1121" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2034" adv="1" patch="1">2034</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only">IY08143</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only">IY08287</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5619">aix-enq-bo(5619)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1122" seq="2000-1122" published="2001-01-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2035" adv="1" patch="1">2035</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07790&amp;apar=only">IY07790</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07831&amp;apar=only">IY07831</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1123" seq="2000-1123" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2036" adv="1" patch="1">2036</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only">IY12638</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5617">aix-pioout-bo(5617)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1124" seq="2000-1124" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2037" adv="1" patch="1">2037</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only">IY12638</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5616">aix-piobe-bo(5616)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1125" seq="2000-1125" published="2001-01-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97336034309944&amp;w=2">20001104 Redhat 6.2 restore exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1914" adv="1">1914</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
        <vers num="6.2e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1126" seq="2000-1126" published="2001-01-09" modified="2017-10-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://www.securityfocus.com/advisories/2850" adv="1" patch="1">HPSBUX0011-130</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1954" adv="1" patch="1">1954</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5655">oval:org.mitre.oval:def:5655</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1127" seq="2000-1127" published="2001-01-09" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143845" adv="1" patch="1">20001108 HP-UX 10.20 resource monitor service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1919" adv="1" patch="1">1919</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1128" seq="2000-1128" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0073.html" adv="1" patch="1">20001103 Elevation of Privileges Exploit with McAfee VirusScan 4.5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1920" adv="1" patch="1">1920</ref>
    </refs>
    <vuln_soft>
      <prod name="virusscan" vendor="mcafee">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1129" seq="2000-1129" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html" adv="1">20001123 McAfee WebShield SMTP vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1999" adv="1" patch="1">1999</ref>
    </refs>
    <vuln_soft>
      <prod name="webshield_smtp" vendor="network_associates">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1130" seq="2000-1130" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html" adv="1">20001123 McAfee WebShield SMTP vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1993" adv="1">1993</ref>
    </refs>
    <vuln_soft>
      <prod name="webshield_smtp" vendor="network_associates">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1131" seq="2000-1131" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0144.html" adv="1">20001110 [hacksware] gbook.cgi remote command execution vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1940" adv="1" patch="1">1940</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5509">gbook-cgi-remote-execution(5509)</ref>
    </refs>
    <vuln_soft>
      <prod name="gbook.cgi" vendor="bill_kendrick">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1132" seq="2000-1132" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0218.html" adv="1" patch="1">20001114 Cgisecurity.com advisory on dcforum</ref>
      <ref source="CONFIRM" url="http://www.dcscripts.com/dcforum/dcfNews/124.html#1">http://www.dcscripts.com/dcforum/dcfNews/124.html#1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1951" adv="1" patch="1">1951</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5533">dcforum-cgi-view-files(5533)</ref>
    </refs>
    <vuln_soft>
      <prod name="dcforum" vendor="dcscripts">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1133" seq="2000-1133" published="2001-01-09" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97353881829760&amp;w=2">20001106 Authentix Security Advisory</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97362374200478&amp;w=2">20001107 Explanation Authentix Input Validation Error</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1907" adv="1" patch="1">1907</ref>
    </refs>
    <vuln_soft>
      <prod name="authentix" vendor="flicks_software">
        <vers num="5.1c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1134" seq="2000-1134" published="2001-01-09" modified="2017-10-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing &lt;&lt; redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc" adv="1" patch="1">FreeBSD-SA-00:76</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P">20011103-02-P</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html">20001028 tcsh: unsafe tempfile in &lt;&lt; redirects</ref>
      <ref source="COMPAQ" url="http://archives.neohapsis.com/archives/tru64/2002-q1/0009.html">SSRT1-41U</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000350">CLA-2000:350</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000354">CLSA-2000:354</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97561816504170&amp;w=2">20001130 [ADV/EXP]: RH6.x root from bash /tmp vuln + MORE</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt">CSSA-2000-042.0</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt">CSSA-2000-043.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001111a">20001111a</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/10277">VU#10277</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3">MDKSA-2000-069</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3">MDKSA-2000:075</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-117.html">RHSA-2000:117</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-121.html">RHSA-2000:121</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/146657">20001128  /bin/sh creates insecure tmp files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1926">1926</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2006" adv="1" patch="1">2006</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4047">oval:org.mitre.oval:def:4047</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num=""/>
      </prod>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.11"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.2e"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1135" seq="2000-1135" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <sols>
      <sol source="nvd">Note: fixed in potato version</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001130" adv="1" patch="1">20001130 DSA-002-1 fsh: symlink attack</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5633">linux-fsh-symlink(5633)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1136" seq="2000-1136" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97502995616099&amp;w=2">20001122 New version of elvis-tiny released</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1984" adv="1" patch="1">1984</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5632">linux-tinyelvis-tmpfiles(5632)</ref>
    </refs>
    <vuln_soft>
      <prod name="elvis_tiny" vendor="debian">
        <vers num="1.4.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1137" seq="2000-1137" published="2001-01-09" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000359">CLA-2000:359-2</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001129">20001129 DSA-001-1 ed: symlink attack</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-076.php3">MDKSA-2000:076</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-123.html" adv="1" patch="1">RHSA-2000:123</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5723">gnu-ed-symlink(5723)</ref>
    </refs>
    <vuln_soft>
      <prod name="ed" vendor="gnu">
        <vers num="2.15"/>
        <vers num="2.16tr"/>
        <vers num="2.18"/>
        <vers num="2.18.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1138" seq="2000-1138" published="2001-01-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97370725220953&amp;w=2">20001108 Lotus Notes R5 clients - no warning for broken signature or encryption</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1925" adv="1">1925</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_notes" vendor="ibm">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1139" seq="2000-1139" published="2001-01-09" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1958" adv="1" patch="1">1958</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-088">MS00-088</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5537">ms-exchange-username-pwd(5537)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1140" seq="2000-1140" published="2001-01-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot system by comparing the results from kill commands with the process listing in the /proc filesystem.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" adv="1">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1908" adv="1" patch="1">1908</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5473">mantrap-hidden-processes(5473)</ref>
    </refs>
    <vuln_soft>
      <prod name="mantrap" vendor="recourse_technologies">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1141" seq="2000-1141" published="2001-01-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 modifies the kernel so that ".." does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5473">mantrap-hidden-processes(5473)</ref>
    </refs>
    <vuln_soft>
      <prod name="mantrap" vendor="recourse_technologies">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1142" seq="2000-1142" published="2001-01-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 generates an error when an attacker cd's to /proc/self/cwd and executes the pwd command, which allows attackers to determine that they are in a honeypot system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5949">mantrap-pwd-reveal-information(5949)</ref>
    </refs>
    <vuln_soft>
      <prod name="mantrap" vendor="recourse_technologies">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1143" seq="2000-1143" published="2001-01-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 hides the first 4 processes that run on a Solaris system, which allows attackers to determine that they are in a honeypot system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html" adv="1">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5473">mantrap-hidden-processes(5473)</ref>
    </refs>
    <vuln_soft>
      <prod name="mantrap" vendor="recourse_technologies">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1144" seq="2000-1144" published="2001-01-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting "/" file system is higher than normal, which allows attackers to determine that they are in a chroot environment.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1909" adv="1" patch="1">1909</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5472">mantrap-inode-disclosure(5472)</ref>
    </refs>
    <vuln_soft>
      <prod name="mantrap" vendor="recourse_technologies">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1145" seq="2000-1145" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/mem and raw disk devices to identify ManTrap processes or modify arbitrary data files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5950">mantrap-identify-processes(5950)</ref>
    </refs>
    <vuln_soft>
      <prod name="mantrap" vendor="recourse_technologies">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1146" seq="2000-1146" published="2001-01-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out of the /proc/self directory and executing various commands such as ls or pwd.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html" adv="1">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1913" adv="1" patch="1">1913</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5528">mantrap-dir-dos(5528)</ref>
    </refs>
    <vuln_soft>
      <prod name="mantrap" vendor="recourse_technologies">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1147" seq="2000-1147" published="2001-01-09" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143070" adv="1" patch="1">20001103 IIS ASP $19.95 hack - IISHack 1.5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1911" adv="1" patch="1">1911</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5510">iis-isapi-asp-bo(5510)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1148" seq="2000-1148" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0072.html" adv="1">20001104 Filesystem Access + VolanoChat = VChat admin (fwd)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0085.html" adv="1">20001106 Re: FW: Filesystem Access + VolanoChat = VChat admin (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1906" adv="1" patch="1">1906</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5465">volanochatpro-plaintext-password(5465)</ref>
    </refs>
    <vuln_soft>
      <prod name="volanochatpro" vendor="volano_llc">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1149" seq="2000-1149" published="2001-01-09" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the "Terminal Server Login Buffer Overflow" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143991" adv="1" patch="1">20001108 [CORE SDI ADVISORY] MS NT4.0 Terminal Server Edition GINA buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1924" adv="1" patch="1">1924</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-087">MS00-087</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5489">nt-termserv-gina-bo(5489)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="terminal_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1150" seq="2000-1150" published="2001-01-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="felix" vendor="xavier_ducrohet">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1151" seq="2000-1151" published="2001-01-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="baxter" vendor="abisoft">
        <vers num="x"/>
        <vers num="y"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1152" seq="2000-1152" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="beos" vendor="be">
        <vers num="4.5"/>
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1153" seq="2000-1153" published="2001-01-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="postmaster" vendor="kenny_carruthers">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1154" seq="2000-1154" published="2001-01-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="robinhood" vendor="joe_kloss">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1155" seq="2000-1155" published="2001-01-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html" adv="1">20001113 beos vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="robinhood" vendor="joe_kloss">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1156" seq="2000-1156" published="2001-01-09" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0115.html" adv="1">20001108 StarOffice 5.2 Temporary Dir Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1922" adv="1" patch="1">1922</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5487">staroffice-tmp-sym-link(5487)</ref>
    </refs>
    <vuln_soft>
      <prod name="staroffice" vendor="sun">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1157" seq="2000-1157" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1901" adv="1">1901</ref>
    </refs>
    <vuln_soft>
      <prod name="sniffer_agent" vendor="network_associates">
        <vers num="3.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1158" seq="2000-1158" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
    </refs>
    <vuln_soft>
      <prod name="sniffer_agent" vendor="network_associates">
        <vers num="3.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1159" seq="2000-1159" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1902" adv="1">1902</ref>
    </refs>
    <vuln_soft>
      <prod name="sniffer_agent" vendor="network_associates">
        <vers num="3.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1160" seq="2000-1160" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html" adv="1">20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1903" adv="1">1903</ref>
    </refs>
    <vuln_soft>
      <prod name="sniffer_agent" vendor="network_associates">
        <vers num="3.0.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1161" seq="2000-1161" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0271.html" adv="1" patch="1">20001120 security problem in AdCycle installation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1969" adv="1" patch="1">1969</ref>
    </refs>
    <vuln_soft>
      <prod name="adcycle" vendor="adcycle">
        <vers num="0.77b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1162" seq="2000-1162" published="2001-01-09" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343">CLSA-2000:343</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt" adv="1" patch="1">CSSA-2000-041</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001123">20001123 ghostscript: symlink attack</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3">MDKSA-2000:074</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-114.html">RHSA-2000:114</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1990" adv="1" patch="1">1990</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5563">ghostscript-sym-link(5563)</ref>
    </refs>
    <vuln_soft>
      <prod name="ghostscript" vendor="aladdin_enterprises">
        <vers num="4.3"/>
        <vers num="5.10.10"/>
        <vers num="5.10.15"/>
        <vers num="5.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1163" seq="2000-1163" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343">CLSA-2000:343</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt">CSSA-2000-041</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001123" adv="1" patch="1">20001123 ghostscript: symlink attack</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3">MDKSA-2000:074</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1991" adv="1" patch="1">1991</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5564">ghostscript-env-variable(5564)</ref>
    </refs>
    <vuln_soft>
      <prod name="ghostscript" vendor="aladdin_enterprises">
        <vers num="4.3"/>
        <vers num="5.10.10"/>
        <vers num="5.10.15"/>
        <vers num="5.10cl"/>
        <vers num="5.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1164" seq="2000-1164" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0253.html" adv="1" patch="1">20001118 WinVNC 3.3.x</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1961" adv="1" patch="1">1961</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5545">winvnc-modify-registry(5545)</ref>
    </refs>
    <vuln_soft>
      <prod name="winvnc" vendor="att">
        <vers num="3.3.3"/>
        <vers num="3.3.3r7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1165" seq="2000-1165" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:02.syslog-ng.asc">FreeBSD-SA-01:02</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0300.html" adv="1" patch="1">20001122 DoS possibility in syslog-ng</ref>
      <ref source="CONFIRM" url="http://www.balabit.hu/products/syslog-ng/">http://www.balabit.hu/products/syslog-ng/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1981" adv="1" patch="1">1981</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5576">balabit-syslog-ng-dos(5576)</ref>
    </refs>
    <vuln_soft>
      <prod name="syslog-ng" vendor="balabit">
        <vers num="1.4.6" prev="1"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1166" seq="2000-1166" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.html" adv="1">20001124 Security problems with TWIG webmail system</ref>
      <ref source="CONFIRM" url="http://twig.screwdriver.net/file.php3?file=CHANGELOG">http://twig.screwdriver.net/file.php3?file=CHANGELOG</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1998" adv="1" patch="1">1998</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5581">twig-php3-script-execute(5581)</ref>
    </refs>
    <vuln_soft>
      <prod name="twig" vendor="twig_development_team">
        <vers num="2.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1167" seq="2000-1167" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:70.ppp-nat.asc">FreeBSD-SA-00:70</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1974" adv="1" patch="1">1974</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5584">freebsd-ppp-bypass-gateway(5584)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1168" seq="2000-1168" published="2001-01-09" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97502498610979&amp;w=2">20001123 IBM HTTP Server 1.3.6 Remote Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1988" adv="1">1988</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="ibm">
        <vers num="1.3.6.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1169" seq="2000-1169" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0195.html" adv="1" patch="1">20001123 OpenSSH Security Advisory (adv.fwd)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000345">CLSA-2000:345</ref>
      <ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0004.html">SuSE-SA:2000:47</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001118">20001118 openssh: possible remote exploit</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-068.php3">MDKSA-2000:068</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-111.html">RHSA-2000:111</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1949" adv="1" patch="1">1949</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5517">openssh-unauthorized-access(5517)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1170" seq="2000-1170" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97439536016554&amp;w=2">20001115 Netsnap Webcam Software Remote Overflow</ref>
      <ref source="CONFIRM" url="http://www.netsnap.com/new.htm">http://www.netsnap.com/new.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1956" adv="1" patch="1">1956</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5534">netsnap-remote-bo(5534)</ref>
    </refs>
    <vuln_soft>
      <prod name="netsnap" vendor="pelesoft">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1171" seq="2000-1171" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the "thesection" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0263.html" adv="1">20001120 CGIForum 1.0 Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1963" adv="1" patch="1">1963</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5553">cgiforum-view-files(5553)</ref>
    </refs>
    <vuln_soft>
      <prod name="cgiforum" vendor="markus_triska">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1172" seq="2000-1172" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0204.html" adv="1">20001110 Advisory: Gaim remote vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1948" adv="1">1948</ref>
    </refs>
    <vuln_soft>
      <prod name="gaim" vendor="rob_flynn">
        <vers num="0.10"/>
        <vers num="0.10.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1173" seq="2000-1173" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0323.html" adv="1">20001122 CyberPatrol - poor credit card protection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1977" adv="1">1977</ref>
    </refs>
    <vuln_soft>
      <prod name="cyberpatrol" vendor="microsys">
        <vers num="4.04.003"/>
        <vers num="4.04.005"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1174" seq="2000-1174" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:81.ethereal.asc">FreeBSD-SA-00:81</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0251.html">20001118 [hacksware] Ethereal 0.8.13 AFS ACL parsing buffer overflow bug</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000342">CLSA-2000:342</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001122a">20001121 ethereal: remote exploit</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-116.html">RHSA-2000:116</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1972" adv="1" patch="1">1972</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5557">ethereal-afs-bo(5557)</ref>
    </refs>
    <vuln_soft>
      <prod name="ethereal" vendor="ethereal_group">
        <vers num="0.8.13" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1175" seq="2000-1175" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/145823" adv="1">20001120 local exploit for linux's Koules1.4 package</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1967" adv="1">1967</ref>
    </refs>
    <vuln_soft>
      <prod name="koules" vendor="jan_hubicka">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1176" seq="2000-1176" published="2001-01-09" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0110.html" adv="1">20001107 Insecure input balidation in YaBB Search.pl</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1921" adv="1">1921</ref>
    </refs>
    <vuln_soft>
      <prod name="yabb" vendor="yabb">
        <vers num="2000-09-11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1177" seq="2000-1177" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0284.html" adv="1" patch="1">20001121 Big Brother Advisory - Fate Research Labs</ref>
      <ref source="CONFIRM" url="http://bb4.com/incident.nov21">http://bb4.com/incident.nov21</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1971" adv="1" patch="1">1971</ref>
    </refs>
    <vuln_soft>
      <prod name="big_brother_network_monitor" vendor="bb4">
        <vers num="1.5d2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1178" seq="2000-1178" published="2001-01-09" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0227.html" adv="1">20001116 Joe's Own Editor File Link Vulnerability</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000356">CLA-2000:356</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97500174210821&amp;w=2">20001121 Immunix OS Security update for joe</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001201">20001201 DSA-003-1 joe: symlink attack</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-072.php3">MDKSA-2000:072</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-110.html">RHSA-2000:110</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1959" adv="1" patch="1">1959</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5546">joe-symlink-corruption(5546)</ref>
    </refs>
    <vuln_soft>
      <prod name="joe" vendor="joseph_allen">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1179" seq="2000-1179" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97440068130051&amp;w=2">20001115 Netopia ISDN Router 650-ST: Viewing of all system logs without login</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1952" adv="1" patch="1">1952</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5536">netopia-view-system-log(5536)</ref>
    </refs>
    <vuln_soft>
      <prod name="650-st_isdn_router" vendor="netopia">
        <vers num="3.3.2_firmware"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1180" seq="2000-1180" published="2001-01-09" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97474521003453&amp;w=2">20001120 vulnerability in Connection Manager Control binary in Oracle</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1968" adv="1" patch="1">1968</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5551">oracle-cmctl-bo(5551)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1181" seq="2000-1181" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0236.html" adv="1" patch="1">20001116 [CORE SDI ADVISORY] RealServer memory contents disclosure</ref>
      <ref source="CONFIRM" url="http://service.real.com/help/faq/security/memory.html">http://service.real.com/help/faq/security/memory.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1957" adv="1" patch="1">1957</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5538">realserver-gain-access(5538)</ref>
    </refs>
    <vuln_soft>
      <prod name="realserver" vendor="realnetworks">
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1182" seq="2000-1182" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0224.html" adv="1">20001116 Possible Watchguard Firebox II DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1953" adv="1" patch="1">1953</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5535">watchguard-firebox-ftp-dos(5535)</ref>
      <ref source="CONFIRM" url="https://www.watchguard.com/support/patches.html">https://www.watchguard.com/support/patches.html</ref>
    </refs>
    <vuln_soft>
      <prod name="firebox_ii" vendor="watchguard">
        <vers num="4.1"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1183" seq="2000-1183" published="2001-01-09" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0219.html">20001115 socks5 remote exploit / linux x86</ref>
    </refs>
    <vuln_soft>
      <prod name="socks_5" vendor="nec">
        <vers num="1.0r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1184" seq="2000-1184" published="2001-01-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes the file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:69.telnetd.v1.1.asc" adv="1" patch="1">FreeBSD-SA-00:69</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5959">telnetd-termcap-dos(5959)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.5.1" edition="stable"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1185" seq="2000-1185" published="2001-01-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0201.html" adv="1">20001113 Rideway PN Telnet DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1938" adv="1">1938</ref>
    </refs>
    <vuln_soft>
      <prod name="ridewaypn" vendor="itserv_incorporated">
        <vers num="6.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1186" seq="2000-1186" published="2001-01-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0221.html" adv="1" patch="1">20001115 Exploit: phf buffer overflow (CGI)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5970">phf-cgi-bo(5970)</ref>
    </refs>
    <vuln_soft>
      <prod name="phf" vendor="phf">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1187" seq="2000-1187" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:66.netscape.asc" adv="1" patch="1">FreeBSD-SA-00:66</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000344">CLSA-2000:344</ref>
      <ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0005.html">SuSE-SA:2000:48</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97500270012529&amp;w=2">20001121 Immunix OS Security update for netscape</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-109.html" adv="1" patch="1">RHSA-2000:109</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5542">netscape-client-html-bo(5542)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.75" prev="1"/>
      </prod>
      <prod name="navigator" vendor="netscape">
        <vers num="4.75" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1188" seq="2000-1188" published="2001-01-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0283.html" adv="1" patch="1">20001120 Cgisecurity Quickstore Shopping cart</ref>
    </refs>
    <vuln_soft>
      <prod name="quikstore" vendor="i-soft">
        <vers num="2.0"/>
        <vers num="2.9.5"/>
        <vers num="2.9.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1189" seq="2000-1189" published="2001-01-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000358">CLA-2000:358</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-082.php3">MDKSA-2000:082-1</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-120.html" adv="1" patch="1">RHSA-2000:120</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5747">pam-localuser-bo(5747)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
        <vers num="7.0" edition=":alpha"/>
        <vers num="7.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1190" seq="2000-1190" published="2001-08-31" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95984116811100&amp;w=2">20000531 Re: strike#2</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/4941.php">linux-imwheel-symlink(4941)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-016.html">RHSA-2000:016</ref>
    </refs>
    <vuln_soft>
      <prod name="imwheel" vendor="jon_atkins">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1191" seq="2000-1191" published="2001-08-31" modified="2017-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html">http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/4366">4366</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7367">htdig-htsearch-path-disclosure(7367)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10526">oval:org.mitre.oval:def:10526</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2000-1192" seq="2000-1192" published="2001-08-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.bttsoftware.co.uk/snmptrap.html" adv="1">http://www.bttsoftware.co.uk/snmptrap.html</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5ZP0C000KC.html" adv="1" patch="1">http://www.securiteam.com/windowsntfocus/5ZP0C000KC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/985">985</ref>
    </refs>
    <vuln_soft>
      <prod name="snmp_trap_watcher" vendor="btt_software">
        <vers num="1.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1193" seq="2000-1193" published="2001-08-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020407-01-I">20020407-01-I</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html" adv="1" patch="1">20000412 Performance Copilot for IRIX 6.5</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4284">irix-pcp-pmcd-dos(4284)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1194" seq="2000-1194" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.mdma.za.net/fk/FK9.zip">http://www.mdma.za.net/fk/FK9.zip</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1227" adv="1">1227</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_server" vendor="argosoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1195" seq="2000-1195" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2000-008.0.txt" adv="1" patch="1">CSSA-2000-008.0</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4225">telnetd-login-bypass(4225)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1196" seq="2000-1196" published="2001-08-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html" adv="1" patch="1">http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html</ref>
      <ref source="MISC" url="http://packetstormsecurity.org/0004-exploits/ooo1.txt" adv="1">http://packetstormsecurity.org/0004-exploits/ooo1.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7362">publishingxpert-pscoerrpage-url(7362)</ref>
    </refs>
    <vuln_soft>
      <prod name="publishingxpert" vendor="netscape">
        <vers num="2.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1197" seq="2000-1197" published="2001-08-31" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:15.imap-uw.asc">FreeBSD-SA-00:15</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95624629924545&amp;w=2">20000420 pop3d/imap DOS (while we're on the subject)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1132">1132</ref>
    </refs>
    <vuln_soft>
      <prod name="imap" vendor="university_of_washington">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1198" seq="2000-1198" published="2001-08-31" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95624629924545&amp;w=2">20000420 pop3d/imap DOS (while we're on the subject)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95634229925906&amp;w=2">20000420 pop3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1132">1132</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="2.53"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1199" seq="2000-1199" published="2001-08-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95659987018649&amp;w=2">20000423 Postgresql cleartext password storage</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1139" adv="1">1139</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4364">postgresql-plaintext-passwords(4364)</ref>
    </refs>
    <vuln_soft>
      <prod name="postgresql" vendor="postgresql">
        <vers num="6.3.2"/>
        <vers num="6.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1200" seq="2000-1200" published="2001-08-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/44430" adv="1">20000201 Windows NT and account list leak ! A new SID usage</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/959" adv="1" patch="1">959</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4015">nt-lsa-domain-sid(4015)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1201" seq="2000-1201" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0085.html" adv="1">20000707 Re: CheckPoint FW1 BUG</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1202" seq="2000-1202" published="2001-08-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/54073" adv="1">20000405 minor issue with IBM HTTPD and /usr/bin/ikeyman</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1092" adv="1" patch="1">1092</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4235">ibm-ikeyman(4235)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server_ssl_module_common" vendor="ibm">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1203" seq="2000-1203" published="2001-08-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=95886062521327&amp;w=2">20000520 Infinite loop in LOTUS NOTE 5.0.3. SMTP SERVER</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/209754">20010823 Lotus Domino DoS solution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3212" adv="1" patch="1">3212</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;start=2002-01-21&amp;end=2002-01-27&amp;mid=209116&amp;threads=1">20010820 Lotus Domino DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7012">lotus-domino-bounced-message-dos(7012)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino" vendor="lotus">
        <vers num="4.6.1"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1204" seq="2000-1204" published="2000-10-13" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/00-10-13" adv="1">http://www.apacheweek.com/issues/00-10-13</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.9"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1205" seq="2000-1205" published="2000-02-01" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code.  NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache.  The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/bugtraq/2002/12/msg00243.html">20021223 Re: 'printenv' XSS vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2002-12/0233.html">20021222 'printenv' XSS vulnerability</ref>
      <ref source="CONFIRM" url="http://httpd.apache.org/info/css-security/apache_specific.html" adv="1" patch="1">http://httpd.apache.org/info/css-security/apache_specific.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=118529436424127&amp;w=2">20070724 printenv.pl(all versions) cross site scripting Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10938">apache-printenv-xss(10938)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/35597">apache-printenv-acuparam-xss(35597)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1206" seq="2000-1206" published="1999-08-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/00-01-07#status">http://www.apacheweek.com/issues/00-01-07#status</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.9"/>
        <vers num="1.3.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1207" seq="2000-1207" published="2000-09-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97034397026473&amp;w=2">20000930 glibc and userhelper - local root</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97063854808796&amp;w=2">20001003 SuSE: userhelper/usermode</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3" adv="1">MDKSA-2000:059</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-075.html" adv="1" patch="1">RHSA-2000:075</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1208" seq="2000-1208" published="2002-08-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96994604300675&amp;w=2">20000925 Format strings: bug #1: BSD-lpr</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/137555">20001004 Immunix OS Security Update for lpr</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5286.php" adv="1" patch="1">lpr-checkremote-format-string(5286)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-066.html" adv="1" patch="1">RHSA-2000:066</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1711">1711</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.7"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1209" seq="2000-1209" published="2002-08-12" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96333895000350&amp;w=2">20000710 MSDE / Re: Default Password Database</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96593218804850&amp;w=2">20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=96644570412692&amp;w=2">20000816 Released Patch: Tumbleweed Worldsecure (MMS) BLANK 'sa' account password</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/273639">20020522 Opty-Way Enterprise includes MSDE with sa &lt;blank></ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200008/0233.html">20000815 MS-SQL 'sa' user exploit code</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q313418">Q313418</ref>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;EN-US;q321081">Q321081</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/1459.php" adv="1" patch="1">mssql-no-sapassword(1459)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/635463" adv="1" patch="1">VU#635463</ref>
      <ref source="CONFIRM" url="http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp">http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/4797">4797</ref>
    </refs>
    <vuln_soft>
      <prod name="insight_manager" vendor="compaq">
        <vers num="7.0" edition="sp1"/>
      </prod>
      <prod name="insight_manager_xe" vendor="compaq">
        <vers num="1.1"/>
        <vers num="1.21"/>
        <vers num="2.1"/>
        <vers num="2.1b"/>
        <vers num="2.1c"/>
        <vers num="2.2"/>
      </prod>
      <prod name="data_engine" vendor="microsoft">
        <vers num="1.0"/>
      </prod>
      <prod name="msde" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1210" seq="2000-1210" published="2002-03-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=95371672300045&amp;w=2">20000322 Security bug in Apache project: Jakarta Tomcat</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/4205.php" adv="1" patch="1">apache-tomcat-file-contents(4205)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1211" seq="2000-1211" published="2000-12-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/5824.php">zope-legacy-names(5824)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3" adv="1" patch="1">MDKSA-2000:083</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-125.html">RHSA-2000:125</ref>
      <ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert" adv="1" patch="1">http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="2.2.0"/>
        <vers num="2.2.0a1"/>
        <vers num="2.2.0b1"/>
        <vers num="2.2.0b2"/>
        <vers num="2.2.0b3"/>
        <vers num="2.2.0b4"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1b1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1212" seq="2000-1212" published="2000-12-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365">CLA-2000:365</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:086">MDKSA-2000:086</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-007">DSA-007</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-135.html">RHSA-2000:135</ref>
      <ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert" adv="1" patch="1">http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5778">zope-image-file(5778)</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="2.2.0"/>
        <vers num="2.2.0a1"/>
        <vers num="2.2.0b1"/>
        <vers num="2.2.0b2"/>
        <vers num="2.2.0b3"/>
        <vers num="2.2.0b4"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1b1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1213" seq="2000-1213" published="2000-10-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html">20001030 Trustix Security Advisory - ping gnupg ypbind</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97249980727834&amp;w=2">20001025 Immunix OS Security Update for ping package</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-087.html" adv="1">RHSA-2000:087</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
      </prod>
      <prod name="iputils" vendor="iputils">
        <vers num="2000-10-10" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1214" seq="2000-1214" published="2000-10-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html">20001030 Trustix Security Advisory - ping gnupg ypbind</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97208562830613&amp;w=2">20001020 Re: [RHSA-2000:087-02] Potential security problems in ping fixed.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97249980727834&amp;w=2">20001025 Immunix OS Security Update for ping package</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5431.php" adv="1" patch="1">ping-buf-bo(5431)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-087.html" adv="1" patch="1">RHSA-2000:087</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1813">1813</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
      </prod>
      <prod name="iputils" vendor="iputils">
        <vers num="2000-10-10" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1215" seq="2000-1215" published="2001-09-19" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100094373621813&amp;w=2">20010919 lotus domino server 5.08 is very gabby</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/984555">VU#984555</ref>
      <ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&amp;Highlight=0,AWHN4A8QWM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&amp;Highlight=0,AWHN4A8QWM</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10685">lotus-domino-information-disclosure(10685)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino" vendor="ibm">
        <vers num="5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1216" seq="2000-1216" published="2000-01-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433499" patch="1">VU#433499</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY07832">IY07832</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7929">aix-portmir-echoerror-bo(7929)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2000-1217" seq="2000-1217" published="2000-11-21" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/818496">VU#818496</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1973">1973</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-089">MS00-089</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5585">win2k-brute-force(5585)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1218" seq="2000-1218" published="2000-04-14" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/458659">VU#458659</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/4280">win2k-dns-resolver(4280)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":alpha"/>
        <vers num="4.0" edition="sp1:alpha"/>
        <vers num="4.0" edition="sp2:alpha"/>
        <vers num="4.0" edition="sp3:alpha"/>
        <vers num="4.0" edition="sp4:alpha"/>
        <vers num="4.0" edition="sp5:alpha"/>
        <vers num="4.0" edition="sp6:alpha"/>
        <vers num="4.0" edition="sp6a:alpha"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1219" seq="2000-1219" published="2000-11-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://gcc.gnu.org/ml/gcc-bugs/2002-05/msg00198.html">[gcc-bugs] 20020506 c/6586: -ftrapv doesn't catch multiplication overflow</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/540517">VU#540517</ref>
    </refs>
    <vuln_soft>
      <prod name="g++" vendor="gnu">
        <vers num="3.3.3" prev="1"/>
      </prod>
      <prod name="gcc" vendor="gnu">
        <vers num="3.3.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1220" seq="2000-1220" published="2000-01-08" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P">20021104-01-P</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2000/Jan/0116.html">20000108 L0pht Advisory: LPD, RH 4.x,5.x,6.x</ref>
      <ref source="L0PHT" url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt">20000108 Quadruple Inverted Backflip</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000109">20000109 lpr -- access control problem and root exploit</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/39001">VU#39001</ref>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/lpd_advisory">20000108 Quadruple Inverted Backflip</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-002.html">RHSA-2000:002</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/927">927</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3841">redhat-lpd-print-control(3841)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0"/>
        <vers num="6.1" edition=":i386"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1221" seq="2000-1221" published="2000-01-08" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P" patch="1">20021104-01-P</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2000-002.html">RHSA-2000:002</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt">A010800-v</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20000109" patch="1">20000109 lpr -- access control problem and root exploit</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/30308">VU#30308</ref>
      <ref source="L0PHT" url="http://www.l0pht.com/advisories/lpd_advisory">20000108 Quadruple Inverted Backflip</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/927">927</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3840">redhat-lpd-auth(3840)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.2" edition=":i386"/>
        <vers num="6.0"/>
        <vers num="6.1" edition=":i386"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.9"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
        <vers num="6.5.12"/>
        <vers num="6.5.13"/>
        <vers num="6.5.14f"/>
        <vers num="6.5.14m"/>
        <vers num="6.5.15f"/>
        <vers num="6.5.15m"/>
        <vers num="6.5.16f"/>
        <vers num="6.5.16m"/>
        <vers num="6.5.17f"/>
        <vers num="6.5.17m"/>
        <vers num="6.5.18f"/>
        <vers num="6.5.18m"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1222" seq="2000-1222" published="2000-12-10" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/17566" adv="1">VU#17566</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6432">aix-sysback-elevate-privileges(6432)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2.1.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1223" seq="2000-1223" published="2000-11-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/671444" adv="1">VU#671444</ref>
    </refs>
    <vuln_soft>
      <prod name="quikstore" vendor="i-soft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1224" seq="2000-1224" published="2000-11-23" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97502269408279&amp;w=2">20001123 RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k))</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/146770">20001123 Re: RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k))</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1986" adv="1">1986</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5568">resin-jsp-source-disclosure(5568)</ref>
    </refs>
    <vuln_soft>
      <prod name="resin" vendor="caucho_technology">
        <vers num="1.1.5"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1225" seq="2000-1225" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html">http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html</ref>
    </refs>
    <vuln_soft>
      <prod name="xitami" vendor="imatix">
        <vers num="2.5_b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1226" seq="2000-1226" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0122.html" adv="1">20000614 Snort 1.6 and nmap 2.54beta1</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0126.html" adv="1" patch="1">20000614 Re: Snort 1.6 and nmap 2.54beta1</ref>
    </refs>
    <vuln_soft>
      <prod name="snort" vendor="snort">
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1227" seq="2000-1227" published="2000-12-31" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/1301">1301</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1228" seq="2000-1228" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" adv="1" patch="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2271" patch="1">2271</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1229" seq="2000-1229" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" adv="1" patch="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1230" seq="2000-1230" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" adv="1" patch="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
      <ref source="MISC" url="http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm" patch="1">http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2274">2274</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1231" seq="2000-1231" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" adv="1" patch="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1232" seq="2000-1232" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" adv="1" patch="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1233" seq="2000-1233" published="2000-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" adv="1" patch="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1234" seq="2000-1234" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html" adv="1">20000106 Phorum 3.0.7 exploits and IDS signatures</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2272" patch="1">2272</ref>
    </refs>
    <vuln_soft>
      <prod name="phorum" vendor="phorum">
        <vers num="3.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1235" seq="2000-1235" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.html" adv="1">20001219 Oracle WebDb engine brain-damagse</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0372.html">20001221 Re: Oracle WebDb engine brain-damagse</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0463.html" adv="1">20001223 Potential Vulnerabilities in Oracle Internet Application Server</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5818.php" patch="1">oracle-webdb-admin-access(5818)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2150" patch="1">2150</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="3.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1236" seq="2000-1236" published="2000-12-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.html">20001219 Oracle WebDb engine brain-damagse</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0372.html">20001221 Re: Oracle WebDb engine brain-damagse</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0463.html">20001223 Potential Vulnerabilities in Oracle Internet Application Server</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5817.php" patch="1">oracle-execute-plsql(5817)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2150" patch="1">2150</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="3.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1237" seq="2000-1237" published="2000-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0282.html" adv="1">20000626 Problems with FTGate</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/4793.php">ftgate-invalid-user-requests(4793)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftgate" vendor="floosietek">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1238" seq="2000-1238" published="2000-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product releases:
BEA Systems Weblogic Server 5.1 SP 7
BEA Systems WebLogic Express 5.1 SP 7</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip" patch="1">ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/5089" patch="1">5089</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5588">weblogic-bypass-auth(5588)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="5.1" edition=":express"/>
        <vers num="5.1" edition="sp1:express"/>
        <vers num="5.1" edition="sp2:express"/>
        <vers num="5.1" edition="sp3:express"/>
        <vers num="5.1" edition="sp4:express"/>
        <vers num="5.1" edition="sp5:express"/>
        <vers num="5.1" edition="sp6:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1239" seq="2000-1239" published="2000-12-31" modified="2017-07-19" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/17085">17085</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3927">tivoli-lcf-file-read(3927)</ref>
    </refs>
    <vuln_soft>
      <prod name="tivoli_management_framework" vendor="ibm">
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1240" seq="2000-1240" published="2000-12-31" modified="2017-07-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/25441">anyportalphp-siteman-information-disclosure(25441)</ref>
    </refs>
    <vuln_soft>
      <prod name="anyportal_php" vendor="anyportal_php">
        <vers num="2000-04-18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1241" seq="2000-1241" published="2000-12-31" modified="2009-10-14" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=25971">http://sourceforge.net/forum/forum.php?forum_id=25971</ref>
    </refs>
    <vuln_soft>
      <prod name="sips" vendor="sips">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1242" seq="2000-1242" published="2000-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="9.0" CVSS_base_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php">http://governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php</ref>
    </refs>
    <vuln_soft>
      <prod name="powerchute" vendor="apc">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1243" seq="2000-1243" published="2000-12-31" modified="2018-10-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html">20000411 Back Door in Commercial Shopping Cart</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0066.html">20000413 Re: Back Door in Commercial Shopping Cart [Stormer Hosting]</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0071.html">20000413 Re: Back Door in Commercial Shopping Cart</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0086.html">20000413 Re: Back Door in Commercial Shopping Cart [RESOLVED]</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/470457/100/0/threaded">20070603 Dansie Cart Script Exploit Reported</ref>
    </refs>
    <vuln_soft>
      <prod name="shopping_cart" vendor="dansie">
        <vers num="3.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1244" seq="2000-1244" published="2000-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the "From" field, which allows remote attackers to bypass virus protection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0158.html">20001110 CA's InoculateIT Agent for Exchange Server</ref>
    </refs>
    <vuln_soft>
      <prod name="inoculateit_agent_for_exchange" vendor="ca">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1245" seq="2000-1245" published="2010-04-05" modified="2010-04-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_ftp_server" vendor="novell">
        <vers num="5.01i" prev="1"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="5.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1246" seq="2000-1246" published="2010-04-05" modified="2010-04-05" severity="Low" CVSS_version="2.0" CVSS_score="3.5" CVSS_base_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" adv="1">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
    </refs>
    <vuln_soft>
      <prod name="netware_ftp_server" vendor="novell">
        <vers num="5.01i" prev="1"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="5.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1247" seq="2000-1247" published="2011-10-04" modified="2017-08-28" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://archive.apache.org/dist/java/java.apache.org-www.tar.gz" patch="1">http://archive.apache.org/dist/java/java.apache.org-www.tar.gz</ref>
      <ref source="MLIST" url="http://marc.info/?l=java-apache-users&amp;m=97036799917909&amp;w=2">[java-apache-users] 20000929 jserv wrapper error</ref>
      <ref source="SREASON" url="http://securityreason.com/securityalert/8412">8412</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/51946">apache-jserv-env-information-disclosure(51946)</ref>
    </refs>
    <vuln_soft>
      <prod name="jserv" vendor="apache">
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2000-1254" seq="2000-1254" published="2016-05-04" modified="2017-02-01" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging improper RSA key generation on 64-bit HP-UX platforms.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://marc.info/?l=openssl-users&amp;m=95961024500509">[openssl-users] 20000529 64 bit problem in RSA_generate_key in 0.9.5a</ref>
      <ref source="MLIST" url="http://www.openwall.com/lists/oss-security/2016/05/04/17">[oss-security] 20160504 broken RSA keys</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/90109">90109</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1035750">1035750</ref>
      <ref source="CONFIRM" url="http://www-01.ibm.com/support/docview.wss?uid=swg21995039">http://www-01.ibm.com/support/docview.wss?uid=swg21995039</ref>
      <ref source="CONFIRM" url="https://git.openssl.org/?p=openssl.git;a=commit;h=db82b8f9bd432a59aea8e1014694e15fc457c2bb">https://git.openssl.org/?p=openssl.git;a=commit;h=db82b8f9bd432a59aea8e1014694e15fc457c2bb</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0001" seq="2001-0001" published="2001-06-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0257.html" adv="1" patch="1">20010213 RFP2101: RFPlutonium to fuel your PHP-Nuke</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6183">php-nuke-elevate-privileges(6183)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0002" seq="2001-0002" published="2001-07-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.guninski.com/chmtempmain.html">http://www.guninski.com/chmtempmain.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2456">2456</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015">MS01-015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5567">ie-chm-execute-files(5567)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920">oval:org.mitre.oval:def:920</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5" prev="1"/>
      </prod>
      <prod name="windows_script_host" vendor="microsoft">
        <vers num="5.1"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0003" seq="2001-0003" published="2001-02-12" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2199" adv="1" patch="1">2199</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-001">MS01-001</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5920">wec-ntlm-authentication(5920)</ref>
    </refs>
    <vuln_soft>
      <prod name="office" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0004" seq="2001-0004" published="2001-02-12" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97897954625305&amp;w=2">20010108 IIS 5.0 allows viewing files using %3F+.htr</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2313">2313</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-004">MS01-004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5903">iis-read-files(5903)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0005" seq="2001-0005" published="2001-02-12" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a012301-1.txt" adv="1">A012301-1</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-002">MS01-002</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5996">powerpoint-execute-code(5996)</ref>
    </refs>
    <vuln_soft>
      <prod name="powerpoint" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0006" seq="2001-0006" published="2001-02-12" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98075221915234&amp;w=2">20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003">MS01-003</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6006">winnt-mutex-dos(6006)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0007" seq="2001-0007" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/155149" adv="1">20010109 NSFOCUS SA2001-01: NetScreen Firewall WebUI Buffer Overflow vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2176" adv="1" patch="1">2176</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5908">netscreen-webui-bo(5908)</ref>
    </refs>
    <vuln_soft>
      <prod name="screen_os" vendor="netscreen">
        <vers num="1.73r"/>
        <vers num="2.1r6"/>
        <vers num="2.5r1"/>
        <vers num="2.10r3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0008" seq="2001-0008" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-01.html" adv="1" patch="1">CA-2001-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2192" adv="1" patch="1">2192</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5911">interbase-backdoor-account(5911)</ref>
    </refs>
    <vuln_soft>
      <prod name="interbase" vendor="borland_software">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
      <prod name="firebird" vendor="firebirdsql">
        <vers num="0.9.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0009" seq="2001-0009" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/154537" adv="1">20010105 Lotus Domino 5.0.5 Web Server vulnerability - reading files outside the web root</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/155124" patch="1">20010109 bugtraq id 2173 Lotus Domino Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2173" adv="1" patch="1">2173</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5899">lotus-domino-directory-traversal(5899)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_server" vendor="lotus">
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0010" seq="2001-0010" published="2001-02-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html" adv="1" patch="1">CA-2001-02</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-026">DSA-026</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2302" adv="1" patch="1">2302</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="p1"/>
        <vers num="8.2.2" edition="p2"/>
        <vers num="8.2.2" edition="p3"/>
        <vers num="8.2.2" edition="p4"/>
        <vers num="8.2.2" edition="p5"/>
        <vers num="8.2.2" edition="p6"/>
        <vers num="8.2.2" edition="p7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0011" seq="2001-0011" published="2001-02-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html" adv="1" patch="1">CA-2001-02</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2307">2307</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="4.9.3"/>
        <vers num="4.9.5" edition="p1"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0012" seq="2001-0012" published="2001-02-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html" adv="1" patch="1">CA-2001-02</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-026">DSA-026</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2321">2321</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="4.9.3"/>
        <vers num="4.9.5" edition="p1"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="p1"/>
        <vers num="8.2.2" edition="p2"/>
        <vers num="8.2.2" edition="p3"/>
        <vers num="8.2.2" edition="p4"/>
        <vers num="8.2.2" edition="p5"/>
        <vers num="8.2.2" edition="p6"/>
        <vers num="8.2.2" edition="p7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0013" seq="2001-0013" published="2001-02-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html" adv="1" patch="1">CA-2001-02</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2309">2309</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="4.9.3"/>
        <vers num="4.9.5" edition="p1"/>
        <vers num="4.9.6"/>
        <vers num="4.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0014" seq="2001-0014" published="2001-02-12" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2326" adv="1" patch="1">2326</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-006">MS01-006</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0015" seq="2001-0015" published="2001-03-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a020501-1.txt" adv="1" patch="1">A020501-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2341">2341</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-007">MS01-007</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6062">win-dde-elevate-privileges(6062)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0016" seq="2001-0016" published="2001-03-12" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html">20010207 Local promotion vulnerability in NT4's NTLM Security Support Provider</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2348">2348</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-008">MS01-008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6076">ntlm-ssp-elevate-privileges(6076)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0017" seq="2001-0017" published="2001-03-12" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2368">2368</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-009">MS01-009</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6103">winnt-pptp-dos(6103)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0018" seq="2001-0018" published="2001-07-21" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://online.securityfocus.com/archive/82/148411">20001202 UDP Ping-pong in Win2k</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-049.shtml">L-049</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-011">MS01-011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6136">win2k-domain-controller-dos(6136)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0019" seq="2001-0019" published="2001-02-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a013101-1.txt" adv="1">A013101-1</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml" adv="1">20010131 Cisco Content Services Switch Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="arrowpoint" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="content_services_switch" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0020" seq="2001-0020" published="2001-02-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a013101-1.txt" adv="1">A013101-1</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml" adv="1">20010131 Cisco Content Services Switch Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2331">2331</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6031">cisco-ccs-file-access(6031)</ref>
    </refs>
    <vuln_soft>
      <prod name="arrowpoint" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="content_services_switch" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0021" seq="2001-0021" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0057.html" adv="1" patch="1">20001206 (SRADV00005) Remote command execution vulnerabilities in MailMan Webmail</ref>
      <ref source="CONFIRM" url="http://www.endymion.com/products/mailman/history.htm">http://www.endymion.com/products/mailman/history.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2063" adv="1" patch="1">2063</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5649">mailman-alternate-templates(5649)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman_webmail" vendor="endymion">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.18"/>
        <vers num="3.0.19"/>
        <vers num="3.0.20"/>
        <vers num="3.0.21"/>
        <vers num="3.0.22"/>
        <vers num="3.0.23"/>
        <vers num="3.0.24"/>
        <vers num="3.0.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0022" seq="2001-0022" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0168.html" adv="1">20001213 Re: Insecure input validation in simplestmail.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2106" adv="1">2106</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5743">http-cgi-simplestguest(5743)</ref>
    </refs>
    <vuln_soft>
      <prod name="simplestguest.cgi" vendor="leif_m._wright">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0023" seq="2001-0023" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0137.html">20001211 Insecure input validation in everythingform.cgi (remote command execution)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2101" adv="1">2101</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5736">http-cgi-everythingform(5736)</ref>
    </refs>
    <vuln_soft>
      <prod name="everythingform.cgi" vendor="leif_m._wright">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0024" seq="2001-0024" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0136.html">20001211 Insecure input validation in simplestmail.cgi (remote command execution)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2102" adv="1">2102</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5739">http-cgi-simplestmail(5739)</ref>
    </refs>
    <vuln_soft>
      <prod name="simplestmail.cgi" vendor="leif_m._wright">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0025" seq="2001-0025" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0143.html">20001211 Insecure input validation in ad.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2103" adv="1">2103</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5741">http-cgi-ad(5741)</ref>
    </refs>
    <vuln_soft>
      <prod name="ad.cgi" vendor="leif_m._wright">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0026" seq="2001-0026" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0134.html" adv="1" patch="1">20001211 DoS vulnerability in rp-pppoe versions &lt;= 2.4</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000357">CLA-2000:357</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-084.php3">MDKSA-2000:084</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-130.html" adv="1" patch="1">RHSA-2000:130</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2098" adv="1" patch="1">2098</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5727">rppppoe-zero-length-dos(5727)</ref>
    </refs>
    <vuln_soft>
      <prod name="pppoe" vendor="roaring_penguin">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0027" seq="2001-0027" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0139.html" adv="1">20001211 mod_sqlpw Password Caching Bug</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5737">proftpd-modsqlpw-unauth-access(5737)</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0028" seq="2001-0028" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html" adv="1" patch="1">20001211 [pkc] remote heap buffer overflow in oops</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-12/0418.html" adv="1" patch="1">FreeBSD-SA-00:79</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2099" adv="1" patch="1">2099</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5725">oops-ftputils-bo(5725)</ref>
    </refs>
    <vuln_soft>
      <prod name="oops_proxy_server" vendor="igor_khasilev">
        <vers num="1.4.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0029" seq="2001-0029" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0158.html">20001212 Stack too ;) Re: [pkc] remote heap buffer overflow in oops</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2099" adv="1" patch="1">2099</ref>
      <ref source="MISC" url="http://zipper.paco.net/~igor/oops/ChangeLog">http://zipper.paco.net/~igor/oops/ChangeLog</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6122">oops-dns-bo(6122)</ref>
    </refs>
    <vuln_soft>
      <prod name="oops_proxy_server" vendor="igor_khasilev">
        <vers num="1.4.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0030" seq="2001-0030" published="2001-02-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2089" adv="1">2089</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5758">foolproof-security-bypass(5758)</ref>
    </refs>
    <vuln_soft>
      <prod name="foolproof_security" vendor="smartstuff">
        <vers num="3.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0031" seq="2001-0031" published="2001-02-16" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0074.html" adv="1">20001207 BroadVision One-To-One Enterprise Path Disclosure Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5661">broadvision-bv1to1-reveal-path(5661)</ref>
    </refs>
    <vuln_soft>
      <prod name="one-to-one_enterprise_server" vendor="broadvision">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0032" seq="2001-0032" published="2001-02-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/149917" adv="1">20001208 format string in ssl dump</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2096" adv="1">2096</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5717">ssldump-format-strings(5717)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssldump" vendor="eric_rescorla">
        <vers num="0.9b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0033" seq="2001-0033" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" adv="1" patch="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5738">kerberos4-user-config(5738)</ref>
    </refs>
    <vuln_soft>
      <prod name="kth_kerberos" vendor="kth">
        <vers num="4"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0034" seq="2001-0034" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" adv="1" patch="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5733">kerberos4-arbitrary-proxy(5733)</ref>
    </refs>
    <vuln_soft>
      <prod name="kth_kerberos" vendor="kth">
        <vers num="4.1.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0035" seq="2001-0035" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" adv="1" patch="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0511.html">20010130 Buffer overflow in old ssh-1.2.2x-afs-kerberosv4 patches</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5734">kerberos4-auth-packet-overflow(5734)</ref>
    </refs>
    <vuln_soft>
      <prod name="kth_kerberos" vendor="kth">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0036" seq="2001-0036" published="2001-02-16" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html" adv="1" patch="1">20001208 Vulnerabilities in KTH Kerberos IV</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html" patch="1">20001210 KTH upgrade and FIX</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-025.html">RHSA-2001:025</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5754">kerberos4-tmpfile-dos(5754)</ref>
    </refs>
    <vuln_soft>
      <prod name="kth_kerberos" vendor="kth">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0037" seq="2001-0037" published="2001-02-16" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0082.html" adv="1">20001207 HomeSeer Directory Traversal Vulnerability</ref>
      <ref source="MISC" url="http://www.keware.com/hsbetachanges.htm">http://www.keware.com/hsbetachanges.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2085" adv="1" patch="1">2085</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5663">homeseer-directory-traversal(5663)</ref>
    </refs>
    <vuln_soft>
      <prod name="homeseer" vendor="keware_technologies">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0038" seq="2001-0038" published="2001-02-16" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0078.html" adv="1">20001207 MetaProducts Offline Explorer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2084" adv="1" patch="1">2084</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5728">offline-explorer-reveal-files(5728)</ref>
    </refs>
    <vuln_soft>
      <prod name="offline_explorer" vendor="metaproducts">
        <vers num="1.0x"/>
        <vers num="1.1x"/>
        <vers num="1.2x"/>
        <vers num="1.3x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0039" seq="2001-0039" published="2001-02-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0071.html" adv="1">20001206 DoS by SMTP AUTH command in IPSwitch IMail server</ref>
      <ref source="CONFIRM" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2083" adv="1" patch="1">2083</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5674">imail-smtp-auth-dos(5674)</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0040" seq="2001-0040" published="2001-02-16" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0066.html" adv="1">20001206 apcupsd 3.7.2 Denial of Service</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-077.php3">MDKSA-2000:077</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2070" adv="1" patch="1">2070</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5654">apc-apcupsd-dos(5654)</ref>
    </refs>
    <vuln_soft>
      <prod name="apcupsd" vendor="apc">
        <vers num="3.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0041" seq="2001-0041" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/catalyst-memleak-pub.shtml" adv="1" patch="1">20001206 Cisco Catalyst Memory Leak Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2072" adv="1" patch="1">2072</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5656">cisco-catalyst-telnet-dos(5656)</ref>
    </refs>
    <vuln_soft>
      <prod name="catos" vendor="cisco">
        <vers num="4.5(2)"/>
        <vers num="4.5(3)"/>
        <vers num="4.5(4)"/>
        <vers num="4.5(5)"/>
        <vers num="4.5(6)"/>
        <vers num="4.5(7)"/>
        <vers num="4.5(8)"/>
        <vers num="4.5(9)"/>
        <vers num="5.1"/>
        <vers num="5.1(1)"/>
        <vers num="5.1(1a)"/>
        <vers num="5.1(2a)"/>
        <vers num="5.2"/>
        <vers num="5.2(1)"/>
        <vers num="5.2(1a)"/>
        <vers num="5.2(2)"/>
        <vers num="5.2(3)"/>
        <vers num="5.2(4)"/>
        <vers num="5.2(5)"/>
        <vers num="5.2(6)"/>
        <vers num="5.2(7)"/>
        <vers num="5.3(1)csx"/>
        <vers num="5.3(1a)csx"/>
        <vers num="5.3(2)csx"/>
        <vers num="5.3(3)csx"/>
        <vers num="5.3(4)csx"/>
        <vers num="5.3(5)csx"/>
        <vers num="5.3(5a)csx"/>
        <vers num="5.3(6)csx"/>
        <vers num="5.4"/>
        <vers num="5.4(1)"/>
        <vers num="5.4(2)"/>
        <vers num="5.4(3)"/>
        <vers num="5.4(4)"/>
        <vers num="5.5"/>
        <vers num="5.5(1)"/>
        <vers num="5.5(2)"/>
        <vers num="5.5(3)"/>
        <vers num="5.5(4)"/>
        <vers num="5.5(4a)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0042" seq="2001-0042" published="2001-02-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/149210" adv="1">20001206 CHINANSL Security Advisory(CSA-200011)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2060" adv="1">2060</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5659">apache-php-disclose-files(5659)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0043" seq="2001-0043" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0053.html" adv="1" patch="1">20001206 (SRADV00006) Remote command execution vulnerabilities in phpGroupWare</ref>
      <ref source="MISC" url="http://sourceforge.net/project/shownotes.php?release_id=17604" patch="1">http://sourceforge.net/project/shownotes.php?release_id=17604</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2069" adv="1" patch="1">2069</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5650">phpgroupware-include-files(5650)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpgroupware" vendor="phpgroupware">
        <vers num="0.9.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0044" seq="2001-0044" published="2001-02-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0064.html" adv="1" patch="1">20001206 (SRADV00007) Local root compromise through Lexmark MarkVision printer drivers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2075" adv="1" patch="1">2075</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5651">markvision-printer-driver-bo(5651)</ref>
    </refs>
    <vuln_soft>
      <prod name="markvision" vendor="lexmark">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0045" seq="2001-0045" published="2001-02-16" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2064" adv="1" patch="1">2064</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-095">MS00-095</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5671">nt-ras-reg-perms(5671)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A500">oval:org.mitre.oval:def:500</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="terminal_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0046" seq="2001-0046" published="2001-02-16" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2066" adv="1" patch="1">2066</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-095">MS00-095</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5672">nt-snmp-reg-perms(5672)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A139">oval:org.mitre.oval:def:139</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0047" seq="2001-0047" published="2001-02-16" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2065">2065</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-095">MS00-095</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5673">nt-mts-reg-perms(5673)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A140">oval:org.mitre.oval:def:140</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="terminal_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0048" seq="2001-0048" published="2001-02-12" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2133" adv="1" patch="1">2133</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-099">MS00-099</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0049" seq="2001-0049" published="2001-02-16" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0079.html" adv="1">20001207 WatchGuard SOHO v2.2.1 DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2082" adv="1">2082</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5665">watchguard-soho-get-dos(5665)</ref>
    </refs>
    <vuln_soft>
      <prod name="soho_firewall" vendor="watchguard">
        <vers num="2.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0050" seq="2001-0050" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:78.bitchx.v1.1.asc">FreeBSD-SA-00:78</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0081.html">20001207 BitchX DNS Overflow Patch</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0086.html">20001207 bitchx/ircd DNS overflow demonstration</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000364">CLA-2000:364</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-079.php3">MDKSA-2000:079</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-126.html">RHSA-2000:126</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2087" adv="1" patch="1">2087</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5701">irc-bitchx-dns-bo(5701)</ref>
    </refs>
    <vuln_soft>
      <prod name="bitchx" vendor="colten_edwards">
        <vers num="1.0c17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0051" seq="2001-0051" published="2001-02-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/149222" adv="1">20001205 IBM DB2 default account and password Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2068" adv="1">2068</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5662">ibm-db2-gain-access(5662)</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="6.1" edition=":linux"/>
        <vers num="6.1" edition=":windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0052" seq="2001-0052" published="2001-02-16" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/149207" adv="1">20001205 IBM DB2 SQL DOS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2067" adv="1">2067</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5664">ibm-db2-dos(5664)</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="6.1" edition=":windows_nt"/>
        <vers num="7.1" edition=":windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0053" seq="2001-0053" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc">NetBSD-SA2000-018</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.html" patch="1">20001218 Trustix Security Advisory - ed, tcsh, and ftpd-BSD</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/advisories/ftpd_replydirname.txt" adv="1" patch="1">20001218</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2124" adv="1" patch="1">2124</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5776">bsd-ftpd-replydirname-bo(5776)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftpd-bsd" vendor="david_madore">
        <vers num="0.2.3"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.5"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0054" seq="2001-0054" published="2001-02-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html" adv="1" patch="1">20001205 (no subject)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97604119024280&amp;w=2">20001205 Serv-U FTP directory traversal vunerability (all versions)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2052" adv="1" patch="1">2052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5639">ftp-servu-homedir-travers(5639)</ref>
    </refs>
    <vuln_soft>
      <prod name="serv-u" vendor="serv-u">
        <vers num="3.0.0.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0055" seq="2001-0055" published="2001-02-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5627">cisco-cbos-syn-packets(5627)</ref>
    </refs>
    <vuln_soft>
      <prod name="cisco_6xx_routers" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="broadband_operating_system" vendor="cisco">
        <vers num="2.3.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0056" seq="2001-0056" published="2001-02-16" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5628">cisco-cbos-invalid-login(5628)</ref>
    </refs>
    <vuln_soft>
      <prod name="broadband_operating_system" vendor="cisco">
        <vers num="2.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0057" seq="2001-0057" published="2001-02-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5629">cisco-cbos-icmp-echo(5629)</ref>
    </refs>
    <vuln_soft>
      <prod name="cisco_6xx_routers" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="broadband_operating_system" vendor="cisco">
        <vers num="2.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0058" seq="2001-0058" published="2001-02-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml" adv="1">20001204 Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5626">cisco-cbos-web-access(5626)</ref>
    </refs>
    <vuln_soft>
      <prod name="cisco_6xx_routers" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="broadband_operating_system" vendor="cisco">
        <vers num="2.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0059" seq="2001-0059" published="2001-02-12" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97720205217707&amp;w=2">20001218 Solaris patchadd(1)  (3) symlink vulnerabilty</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2127" adv="1">2127</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5789">solaris-patchadd-symlink(5789)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0060" seq="2001-0060" published="2001-02-12" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0337.html" adv="1" patch="1">20001209 Trustix Security Advisory - stunnel</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000363">CLA-2000:363</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-009">DSA-009</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-129.html">RHSA-2000:129</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/151719" adv="1" patch="1">20001218 Stunnel format bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2128" adv="1" patch="1">2128</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5807">stunnel-format-logfile(5807)</ref>
    </refs>
    <vuln_soft>
      <prod name="stunnel" vendor="stunnel">
        <vers num="3.3"/>
        <vers num="3.4a"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0061" seq="2001-0061" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc" adv="1" patch="1">FreeBSD-SA-00:77</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2130" adv="1" patch="1">2130</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6106">procfs-elevate-privileges(6106)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5.1"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0062" seq="2001-0062" published="2001-02-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc" adv="1" patch="1">FreeBSD-SA-00:77</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2131" adv="1" patch="1">2131</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6107">procfs-mmap-dos(6107)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5.1"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0063" seq="2001-0063" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc" adv="1" patch="1">FreeBSD-SA-00:77</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2132" adv="1" patch="1">2132</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6108">procfs-access-control-bo(6108)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5.1"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0064" seq="2001-0064" published="2001-02-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0315.html" adv="1" patch="1">20001219 def-2000-03: MDaemon 3.5.0 DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2134" adv="1" patch="1">2134</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="3.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0065" seq="2001-0065" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0189.html">20001213 Potential Buffer Overflow vulnerability in bftpd-1.0.13</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5775">bftpd-site-chown-bo(5775)</ref>
    </refs>
    <vuln_soft>
      <prod name="bftpd" vendor="max-wilhelm_bruker">
        <vers num="1.0.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0066" seq="2001-0066" published="2001-02-16" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0356.html" adv="1">20001126 [MSY] S(ecure)Locate heap corruption vulnerability</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000369">CLA-2001:369</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001217a">DSA-005-1</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-085.php3">MDKSA-2000:085</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-128.html">RHSA-2000:128</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2004" adv="1" patch="1">2004</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2001-February/000144.html">TLSA2001002-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5594">slocate-heap-execute-code(5594)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_locate" vendor="kevin_lindsay">
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0067" seq="2001-0067" published="2001-02-12" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-081.php3" patch="1">MDKSA-2000:081</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?mid=150957&amp;end=2001-02-03&amp;fromthread=1&amp;start=2001-01-28&amp;threads=0&amp;list=1&amp;" adv="1">20001214 J-Pilot Permissions Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5762">jpilot-perms(5762)</ref>
    </refs>
    <vuln_soft>
      <prod name="jpilot" vendor="judd_montgomery">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0068" seq="2001-0068" published="2001-02-12" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0241.html">20001215 Security Hole of MRJ 2.2.3 (Mac OS Runtime for Java) - Inconsistent Use of CODEBASE and ARCHIVE Attributes -</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5784">mrj-runtime-malicious-applets(5784)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_runtime_for_java" vendor="apple">
        <vers num="2.2.3" edition=":java"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0069" seq="2001-0069" published="2001-02-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225" patch="1">DSA-008-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2151" adv="1" patch="1">2151</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5809">dialog-symlink(5809)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" edition=":68k"/>
        <vers num="2.2" edition=":alpha"/>
        <vers num="2.2" edition=":arm"/>
        <vers num="2.2" edition=":powerpc"/>
        <vers num="2.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0070" seq="2001-0070" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0143.html" adv="1" patch="1">20001226 1st Up Mail Server v4.1 Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2152" adv="1">2152</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5808">1stup-mail-server-bo(5808)</ref>
    </refs>
    <vuln_soft>
      <prod name="1st_up_mail_server" vendor="upland_solutions">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0071" seq="2001-0071" published="2001-02-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368">CLA-2000:368</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225b">DSA-010-1</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3">MDKSA-2000-087</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-131.html" adv="1" patch="1">RHSA-2000:131</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152197" adv="1" patch="1">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2141" adv="1" patch="1">2141</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5802">gnupg-detached-sig-modify(5802)</ref>
    </refs>
    <vuln_soft>
      <prod name="privacy_guard" vendor="gnu">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.3b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0072" seq="2001-0072" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368">CLA-2000:368</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225b">DSA-010-1</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3">MDKSA-2000-087</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-131.html">RHSA-2000:131</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152197">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2153" adv="1" patch="1">2153</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5803">gnupg-reveal-private(5803)</ref>
    </refs>
    <vuln_soft>
      <prod name="privacy_guard" vendor="gnu">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.3b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0073" seq="2001-0073" published="2001-02-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/153188" adv="1">20001226 buffer overflow in libsecure (NSA Security-enhanced Linux)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2154" adv="1">2154</ref>
    </refs>
    <vuln_soft>
      <prod name="security-enhanced_linux" vendor="nsa">
        <vers num="slinux_2000-12-18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0074" seq="2001-0074" published="2001-02-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/153007" adv="1">20001223 Technote</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2155" adv="1">2155</ref>
    </refs>
    <vuln_soft>
      <prod name="technote" vendor="technote_inc">
        <vers num="2000"/>
        <vers num="2001"/>
        <vers num="pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0075" seq="2001-0075" published="2001-02-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/153212" adv="1">20001227 [Ksecurity Advisory] main.cgi in technote</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2156" adv="1">2156</ref>
    </refs>
    <vuln_soft>
      <prod name="technote" vendor="technote_inc">
        <vers num="2000"/>
        <vers num="2001"/>
        <vers num="pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0076" seq="2001-0076" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0483.html" adv="1" patch="1">20001228 Remote vulnerability in Ikonboard upto version 2.1.7b</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2157" adv="1" patch="1">2157</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5819">http-cgi-ikonboard(5819)</ref>
    </refs>
    <vuln_soft>
      <prod name="ikonboard" vendor="ikonboard.com">
        <vers num="2.1.7b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0077" seq="2001-0077" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html" adv="1">20001212 Two Holes in Sun Cluster 2.x</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6123">clustmon-no-authentication(6123)</ref>
    </refs>
    <vuln_soft>
      <prod name="cluster" vendor="sun">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0078" seq="2001-0078" published="2001-02-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html" adv="1">20001212 Two Holes in Sun Cluster 2.x</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6125">ha-nfs-symlink(6125)</ref>
    </refs>
    <vuln_soft>
      <prod name="cluster" vendor="sun">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0079" seq="2001-0079" published="2001-02-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0174.html" adv="1">20001213 STM symlink Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="support_tools_manager" vendor="hp">
        <vers num="a.22.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0080" seq="2001-0080" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/catalyst-ssh-protocolmismatch-pub.shtml" adv="1" patch="1">20001213 Cisco Catalyst SSH Protocol Mismatch Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2117">2117</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5760">cisco-catalyst-ssh-mismatch(5760)</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_4000" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_5000" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_6000" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0081" seq="2001-0081" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://active.ncipher.com/updates/advisory.txt" adv="1" patch="1">http://active.ncipher.com/updates/advisory.txt</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html" adv="1" patch="1">20001212 nCipher Security Advisory: Operator Cards unexpectedly recoverable</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5999">ncipher-recover-operator-cards(5999)</ref>
    </refs>
    <vuln_soft>
      <prod name="ncipher" vendor="ncipher">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0082" seq="2001-0082" published="2001-02-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0271.html" adv="1">20001218 FireWall-1 Fastmode Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0083" seq="2001-0083" published="2001-02-12" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q281256">Q281256</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-097">MS00-097</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5785">mediaservices-dropped-connection-dos(5785)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_services" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0084" seq="2001-0084" published="2001-02-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0498.html">20010102 gtk+ security hole.</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html">20010103 Claimed vulnerability in GTK_MODULES</ref>
      <ref source="MISC" url="http://www.gtk.org/setuid.html">http://www.gtk.org/setuid.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2165" adv="1" patch="1">2165</ref>
    </refs>
    <vuln_soft>
      <prod name="gtk+" vendor="gtk">
        <vers num="1.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0085" seq="2001-0085" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0083.html" adv="1">HPSBUX0012-135</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2170" adv="1" patch="1">2170</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5793">hpux-kermit-bo(5793)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0086" seq="2001-0086" published="2001-02-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0160.html" adv="1">20001212 Security Advisory: Subscribe Me Lite 1.0 - 2.0 Unix or 1.0 - 2.0 NT and below.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2108" adv="1">2108</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5735">subscribemelite-gain-admin-access(5735)</ref>
    </refs>
    <vuln_soft>
      <prod name="subscribe_me_lite" vendor="cgi_script_center">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0087" seq="2001-0087" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0295.html" adv="1">20001219 itetris[v1.6.2] local root exploit (system()+../ protection)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2139" adv="1" patch="1">2139</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5795">itetris-svgalib-path(5795)</ref>
    </refs>
    <vuln_soft>
      <prod name="itetris" vendor="michael_glickman">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0088" seq="2001-0088" published="2001-02-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0025.html" adv="1">20001202 Bypassing admin authentication in phpWebLog</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2047" adv="1">2047</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5625">phpweblog-bypass-authentication(5625)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpweblog" vendor="jason_hines">
        <vers num="0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0089" seq="2001-0089" published="2001-02-16" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the "File Upload via Form" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-093">MS00-093</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5615">ie-form-file-upload(5615)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.01"/>
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0090" seq="2001-0090" published="2001-02-16" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2046" adv="1" patch="1">2046</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-093">MS00-093</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5614">ie-print-template(5614)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0091" seq="2001-0091" published="2001-02-16" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-093">MS00-093</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6085">ie-scriptlet-rendering-read-files(6085)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0092" seq="2001-0092" published="2001-02-16" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-093">MS00-093</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6086">ie-frame-verification-read-files(6086)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0093" seq="2001-0093" published="2001-02-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc" adv="1">NetBSD-SA2000-017</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0094" seq="2001-0094" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:25.kerberosIV.asc">FreeBSD-SA-01:25</ref>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc" adv="1" patch="1">NetBSD-SA2000-017</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5734">kerberos4-auth-packet-overflow(5734)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0095" seq="2001-0095" published="2001-02-12" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0313.html" adv="1">20001218 Catman file clobbering vulnerability Solaris 2.x</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5788">solaris-catman-symlink(5788)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0096" seq="2001-0096" published="2001-02-12" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-100">MS00-100</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5823">iis-web-form-submit(5823)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0097" seq="2001-0097" published="2001-02-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152403">20001221 Infinite InterChange DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2140" adv="1">2140</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5798">infinite-interchange-dos(5798)</ref>
    </refs>
    <vuln_soft>
      <prod name="infinite_interchange" vendor="infinite">
        <vers num="3.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0098" seq="2001-0098" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".."  string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html" patch="1">20001219 def-2000-04: Bea WebLogic Server dotdot-overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2138" adv="1" patch="1">2138</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5782">weblogic-dot-bo(5782)</ref>
    </refs>
    <vuln_soft>
      <prod name="weblogic_server" vendor="bea">
        <vers num="4.5.2" prev="1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0099" seq="2001-0099" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html" adv="1" patch="1">20001221 BS Scripts Vulnerabilities</ref>
      <ref source="MISC" url="http://www.stanback.net/" patch="1">http://www.stanback.net/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5796">bsguest-cgi-execute-commands(5796)</ref>
    </refs>
    <vuln_soft>
      <prod name="bsguest.cgi" vendor="brian_stanback">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0100" seq="2001-0100" published="2001-02-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html" adv="1" patch="1">20001221 BS Scripts Vulnerabilities</ref>
      <ref source="MISC" url="http://www.stanback.net/" patch="1">http://www.stanback.net/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5797">bslist-cgi-execute-commands(5797)</ref>
    </refs>
    <vuln_soft>
      <prod name="bslist.cgi" vendor="brian_stanback">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0101" seq="2001-0101" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHBA-2000-106.html" adv="1">RHBA-2000:106-04</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html" patch="1">TLSA2000024-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7455">fetchmail-authenticate-gssapi(7455)</ref>
    </refs>
    <vuln_soft>
      <prod name="fetchmail" vendor="fetchmail">
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.1.0"/>
        <vers num="5.1.4"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.3"/>
        <vers num="5.3.8"/>
        <vers num="5.4.0"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0102" seq="2001-0102" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">"Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users &amp; Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0497.html" adv="1">20001229 Mac OS 9 Multiple Users Control Panel Password Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5830">macos-multiple-users(5830)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os" vendor="apple">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0103" seq="2001-0103" published="2001-02-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2107" adv="1">2107</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5744">coffeecup-ftp-weak-encryption(5744)</ref>
    </refs>
    <vuln_soft>
      <prod name="coffeecup_direct_ftp" vendor="coffeecup_software">
        <vers num="1.0"/>
      </prod>
      <prod name="coffeecup_free_ftp" vendor="coffeecup_software">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0104" seq="2001-0104" published="2001-02-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/151156">20001214 Bypass MDaemon 3.5.1 "Lock Server" Protection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2115" adv="1">2115</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5763">mdaemon-lock-bypass-password(5763)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0105" seq="2001-0105" published="2001-02-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0079.html" patch="1">HPSBUX0012-134</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5773">hp-top-sys-files(5773)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10"/>
        <vers num="11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0106" seq="2001-0106" published="2001-02-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0009.html" adv="1" patch="1">HPSBUX0101-136</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5904">hp-inetd-swait-dos(5904)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.04" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0107" seq="2001-0107" published="2001-03-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Veritas Backup agent on Linux allows remote attackers to cause a denial of service by establishing a connection without sending any data, which causes the process to hang.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97958921407182&amp;w=2">20010115 Veritas BackupExec (remote DoS)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2204" adv="1">2204</ref>
    </refs>
    <vuln_soft>
      <prod name="backup" vendor="symantec_veritas">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0108" seq="2001-0108" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000373">CLA-2001:373</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97957961212852">20010112 PHP Security Advisory - Apache Module bugs</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-020">DSA-020</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-013.php3">MDKSA-2001:013</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-136.html">RHSA-2000:136</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2206" adv="1" patch="1">2206</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5940">php-htaccess-unauth-access(5940)</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0109" seq="2001-0109" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0226.html" adv="1">20010113 Serious security flaw in SuSE rctab</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0272.html">20010117 Re: Serious security flaw in SuSE rctab</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2207" adv="1" patch="1">2207</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5945">rctab-elevate-privileges(5945)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0110" seq="2001-0110" published="2001-03-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0228.html">20010114 Vulnerability in jaZip.</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-017" patch="1">DSA-017</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2209" adv="1">2209</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5942">jazip-display-bo(5942)</ref>
    </refs>
    <vuln_soft>
      <prod name="jazip" vendor="iomega">
        <vers num="0.32.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0111" seq="2001-0111" published="2001-03-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97958269320974&amp;w=2">20010114 [MSY] Multiple vulnerabilities in splitvt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-014" patch="1">DSA-014-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2210" adv="1" patch="1">2210</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5948">splitvt-perserc-format-string(5948)</ref>
    </refs>
    <vuln_soft>
      <prod name="splitvt" vendor="sam_lantinga">
        <vers num="1.6.4"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" edition=":68k"/>
        <vers num="2.2" edition=":alpha"/>
        <vers num="2.2" edition=":arm"/>
        <vers num="2.2" edition=":powerpc"/>
        <vers num="2.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0112" seq="2001-0112" published="2001-03-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97958269320974&amp;w=2">20010114 [MSY] Multiple vulnerabilities in splitvt</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-014" patch="1">DSA-014</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2210" adv="1" patch="1">2210</ref>
    </refs>
    <vuln_soft>
      <prod name="splitvt" vendor="sam_lantinga">
        <vers num="1.6.4" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" edition=":68k"/>
        <vers num="2.2" edition=":alpha"/>
        <vers num="2.2" edition=":arm"/>
        <vers num="2.2" edition=":powerpc"/>
        <vers num="2.2" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0113" seq="2001-0113" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html">20010116 Vulnerabilities in OmniHTTPd default installation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2211" adv="1" patch="1">2211</ref>
    </refs>
    <vuln_soft>
      <prod name="omnihttpd" vendor="omnicron">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0114" seq="2001-0114" published="2001-03-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html">20010116 Vulnerabilities in OmniHTTPd default installation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2211" adv="1" patch="1">2211</ref>
    </refs>
    <vuln_soft>
      <prod name="omnihttpd" vendor="omnicron">
        <vers num="2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0115" seq="2001-0115" published="2001-03-12" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97934312727101&amp;w=2">20010111 Solaris Arp Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97957435729702&amp;w=2">20010112 arp exploit</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/200&amp;type=0&amp;nav=sec.sba" adv="1" patch="1">00200</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2193" adv="1" patch="1">2193</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5928">solaris-arp-bo(5928)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0116" seq="2001-0116" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-006.php3" patch="1">MDKSA-2001:006</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2188" adv="1" patch="1">2188</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5917">linux-gpm-symlink(5917)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0117" seq="2001-0117" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2000-70-028-01">IMNX-2000-70-028-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/579928">VU#579928</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-008.php3" patch="1">MDKSA-2001:008-1</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-116.html">RHSA-2001:116</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2191" adv="1" patch="1">2191</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5914">linux-diffutils-sdiff-symlink(5914)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.1"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0118" seq="2001-0118" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-005.php3" patch="1">MDKSA-2001-005</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2195" adv="1" patch="1">2195</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5925">rdist-symlink(5925)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0119" seq="2001-0119" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-004.php3" patch="1">MDKSA-2001:004</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2194" adv="1" patch="1">2194</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5924">gettyps-symlink(5924)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0120" seq="2001-0120" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-007.php3" patch="1">MDKSA-2001:007</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2196" adv="1" patch="1">2196</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5927">shadow-utils-useradd-symlink(5927)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0121" seq="2001-0121" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0071.html" adv="1">20010108 def-2001-01: ImageCast IC3 Control Center DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2174" adv="1">2174</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5901">storagesoft-imagecast-dos(5901)</ref>
    </refs>
    <vuln_soft>
      <prod name="imagecast_ic3" vendor="storagesoft">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0122" seq="2001-0122" published="2001-03-13" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0079.html" adv="1" patch="1">20010108 def-2001-02: IBM Websphere 3.52 Kernel Leak DoS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0061.html">20010307 def-2001-02: IBM HTTP Server Kernel Leak DoS (re-release)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2175" adv="1" patch="1">2175</ref>
      <ref source="CONFIRM" url="http://www-4.ibm.com/software/webservers/security.html">http://www-4.ibm.com/software/webservers/security.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5900">ibm-websphere-dos(5900)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="ibm">
        <vers num="1.3.12.2"/>
      </prod>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="3.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0123" seq="2001-0123" published="2001-03-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97905792214999&amp;w=2">20010107 Cgisecurity.com Advisory #3.1</ref>
      <ref source="CONFIRM" url="http://www.extropia.com/hacks/bbs_security.html">http://www.extropia.com/hacks/bbs_security.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2177" adv="1" patch="1">2177</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5906">http-cgi-bbs-forum(5906)</ref>
    </refs>
    <vuln_soft>
      <prod name="bbs_forum.cgi" vendor="extropia">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0124" seq="2001-0124" published="2001-03-12" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97908386502156&amp;w=2">20010109 Solaris /usr/lib/exrecover buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2179" adv="1" patch="1">2179</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5913">solaris-exrecover-bo(5913)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0125" seq="2001-0125" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-01/0543.html">FreeBSD-SA-01:17</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97846489313059&amp;w=2">20001231 Advisory: exmh symlink vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97958594330100&amp;w=2">20010112 exmh security vulnerability</ref>
      <ref source="CONFIRM" url="http://www.beedub.com/exmh/symlink.html" adv="1" patch="1">http://www.beedub.com/exmh/symlink.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-022">DSA-022</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-015.php3" patch="1">MDKSA-2001:015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5829">exmh-error-symlink(5829)</ref>
    </refs>
    <vuln_soft>
      <prod name="exmh" vendor="exmh">
        <vers num="2.2" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0126" seq="2001-0126" published="2001-03-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97906670012796&amp;w=2">20010109 Oracle XSQL servlet and xml-stylesheet allow executing java on the web server</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98027700625521&amp;w=2">20010123 Patch for Potential Vulnerability in Oracle XSQL Servlet</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5905">oracle-xsql-execute-code(5905)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0127" seq="2001-0127" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0236.html" adv="1">20010115 Flash plugin write-overflow</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/451096">VU#451096</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2214" adv="1">2214</ref>
    </refs>
    <vuln_soft>
      <prod name="flash" vendor="oliver_debon">
        <vers num="0.4.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0128" seq="2001-0128" published="2001-03-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc" adv="1" patch="1">FreeBSD-SA-01:06</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365">CLA-2000:365</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2000/20001219" adv="1" patch="1">DSA-006-1</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-083.php3" patch="1">MDKSA-2000-083</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-127.html">RHSA-2000:127</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5777">zope-calculate-roles(5777)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_powertools" vendor="redhat">
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
      <prod name="zope" vendor="zope">
        <vers num="2.2.4" prev="1"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0129" seq="2001-0129" published="2001-03-12" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97975486527750&amp;w=2">20010117 [pkc] remote heap overflow in tinyproxy</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-018" patch="1">DSA-018</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2217" adv="1" patch="1">2217</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5954">tinyproxy-remote-bo(5954)</ref>
    </refs>
    <vuln_soft>
      <prod name="tinyproxy" vendor="tinyproxy">
        <vers num="1.3.2" prev="1"/>
        <vers num="1.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0130" seq="2001-0130" published="2001-03-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html" adv="1">http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6207">lotus-html-bo(6207)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_r5_client" vendor="lotus">
        <vers num="5.04"/>
        <vers num="5.05"/>
      </prod>
      <prod name="domino_r5_server" vendor="lotus">
        <vers num="5.04"/>
        <vers num="5.05"/>
        <vers num="5.06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0131" seq="2001-0131" published="2001-03-12" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-021" adv="1" patch="1">DSA-021</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2182" adv="1" patch="1">2182</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5926">linux-apache-symlink(5926)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0132" seq="2001-0132" published="2001-03-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html" adv="1">20010114 Trend Micro's VirusWall: Multiple vunerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2213" adv="1">2213</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.0.1"/>
        <vers num="3.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0133" seq="2001-0133" published="2001-03-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html" adv="1">20010114 Trend Micro's VirusWall: Multiple vunerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2212" adv="1">2212</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.0.1"/>
        <vers num="3.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0134" seq="2001-0134" published="2001-03-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97967435023835&amp;w=2">20010116 iXsecurity.20001120.compaq-authbo.a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2200" adv="1" patch="1">2200</ref>
      <ref source="COMPAQ" url="http://www5.compaq.com/products/servers/management/agentsecurity.html" patch="1">SSRT0705</ref>
    </refs>
    <vuln_soft>
      <prod name="armada_insight_manager" vendor="compaq">
        <vers num="4.20"/>
        <vers num="4.20j"/>
      </prod>
      <prod name="enterprise_volume_manager-command_scripter" vendor="compaq">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
      <prod name="foundation_agents" vendor="compaq">
        <vers num="1.0"/>
        <vers num="2.1"/>
        <vers num="4.0"/>
        <vers num="4.90"/>
      </prod>
      <prod name="insight_management_agent" vendor="compaq">
        <vers num="4.37e"/>
      </prod>
      <prod name="insight_management_desktop_web_agent" vendor="compaq">
        <vers num="3.7"/>
      </prod>
      <prod name="insight_manager_lc" vendor="compaq">
        <vers num="1.3c"/>
        <vers num="1.50a"/>
      </prod>
      <prod name="insight_manager_xe" vendor="compaq">
        <vers num="1.0"/>
        <vers num="1.21"/>
      </prod>
      <prod name="intelligent_cluster_administrator" vendor="compaq">
        <vers num="1.0"/>
        <vers num="2.1"/>
      </prod>
      <prod name="management_agents" vendor="compaq">
        <vers num="4.30j"/>
        <vers num="4.35j"/>
        <vers num="4.36e"/>
        <vers num="4.36j"/>
      </prod>
      <prod name="open_san_manager" vendor="compaq">
        <vers num="1.0"/>
      </prod>
      <prod name="sanworks_resource_monitor" vendor="compaq">
        <vers num="1.0"/>
      </prod>
      <prod name="storage_allocation_reporter" vendor="compaq">
        <vers num="1.0"/>
      </prod>
      <prod name="survey_utility" vendor="compaq">
        <vers num="2.17"/>
        <vers num="2.18"/>
        <vers num="2.33"/>
      </prod>
      <prod name="system_healthcheck" vendor="compaq">
        <vers num="3.0"/>
      </prod>
      <prod name="unix" vendor="digital">
        <vers num="4.0f"/>
        <vers num="4.0g"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0135" seq="2001-0135" published="2001-03-12" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97933458505857&amp;w=2">20010112 UltraBoard cgi directory permission problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2197" adv="1">2197</ref>
    </refs>
    <vuln_soft>
      <prod name="ultraboard" vendor="ultrascripts">
        <vers num="2.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0136" seq="2001-0136" published="2001-03-12" modified="2018-02-07" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0122.html" adv="1">20010109 Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0132.html">20010110 Re: Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html">20010213 Trustix Security Advisory - proftpd, kernel</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000380">CLA-2001:380</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-029" adv="1">DSA-029</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3">MDKSA-2001:021</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152206" adv="1">20001220 ProFTPD 1.2.0 Memory leakage - denial of service</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5801" adv="1">proftpd-size-memory-leak(5801)</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd">
        <vers num="1.2.0" edition="rc2"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num=""/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0137" seq="2001-0137" published="2001-03-12" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97958100816503&amp;w=2">20010115 Windows Media Player 7 and IE java vulnerability - executing arbitrary programs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2203" adv="1" patch="1">2203</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-010">MS01-010</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5937">win-mediaplayer-arbitrary-code(5937)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0138" seq="2001-0138" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-016">DSA-016</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-001.php3">MDKSA-2001-001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2189" adv="1" patch="1">2189</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5915">linux-wuftpd-privatepw-symlink(5915)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" edition=":68k"/>
        <vers num="2.2" edition=":alpha"/>
        <vers num="2.2" edition=":arm"/>
        <vers num="2.2" edition=":powerpc"/>
        <vers num="2.2" edition=":sparc"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0139" seq="2001-0139" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-001.0.txt" adv="1">CSSA-2001-001.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-010.php3" adv="1" patch="1">MDKSA-2001:010</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2190" adv="1" patch="1">2190</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5916">linux-inn-symlink(5916)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_desktop" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" edition=":68k"/>
        <vers num="2.2" edition=":alpha"/>
        <vers num="2.2" edition=":arm"/>
        <vers num="2.2" edition=":sparc"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0140" seq="2001-0140" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-002.php3" patch="1">MDKSA-2001:002</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2183" adv="1" patch="1">2183</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5922">tcpdump-arpwatch-symlink(5922)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0141" seq="2001-0141" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-002.0.txt" patch="1">CSSA-2001-002.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-011" patch="1">DSA-011</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-009.php3" patch="1">MDKSA-2001:009</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-050.html">RHSA-2001:050</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2187" adv="1" patch="1">2187</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5918">linux-mgetty-symlink(5918)</ref>
    </refs>
    <vuln_soft>
      <prod name="mgetty" vendor="gert_doering">
        <vers num="1.1.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0142" seq="2001-0142" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0212.html" patch="1">20010112 Trustix Security Advisory - diffutils squid</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-019">DSA-019</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-003.php3" adv="1" patch="1">MDKSA-2001:003</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2184" adv="1" patch="1">2184</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5921">squid-email-symlink(5921)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="squid_web_proxy" vendor="national_science_foundation">
        <vers num="2.3_stable4"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.1"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0143" seq="2001-0143" published="2001-03-12" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-011.php3" patch="1">MDKSA-2001:011</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2186" adv="1" patch="1">2186</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5923">linuxconf-vpop3d-symlink(5923)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0144" seq="2001-0144" published="2001-03-12" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98168366406903&amp;w=2">20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector</ref>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_ssh1crc.html" adv="1" patch="1">20010208 Remote vulnerability in SSH daemon crc32 compensation attack detector</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-35.html">CA-2001-35</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2347" adv="1" patch="1">2347</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6083">ssh-deattack-overwrite-memory(6083)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
      </prod>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0145" seq="2001-0145" published="2001-05-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a022301-1.txt" adv="1" patch="1">A022301-1</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-012">MS01-012</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0146" seq="2001-0146" published="2001-06-02" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/796584">VU#796584</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2440">2440</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2441">2441</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-014">MS01-014</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6171">iis-malformed-url-dos(6171)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6172">exchange-malformed-url-dos(6172)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0147" seq="2001-0147" published="2001-05-03" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-013">MS01-013</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0148" seq="2001-0148" published="2001-06-02" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0000.html" adv="1" patch="1">20010101 Windows Media Player 7 and IE vulnerability - executing arbitrary programs</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015">MS01-015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6227">media-player-execute-commands(6227)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0149" seq="2001-0149" published="2001-06-02" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0305.html" adv="1" patch="1">20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=96999020527583&amp;w=2">20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1718">1718</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015">MS01-015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5293">ie-getobject-expose-files(5293)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0150" seq="2001-0150" published="2001-06-02" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2463">2463</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015">MS01-015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6230">ie-telnet-execute-commands(6230)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0151" seq="2001-0151" published="2001-06-02" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-016">MS01-016</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6205">iis-webdav-dos(6205)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A90">oval:org.mitre.oval:def:90</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0152" seq="2001-0152" published="2001-05-03" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-019">MS01-019</ref>
    </refs>
    <vuln_soft>
      <prod name="plus" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0153" seq="2001-0153" published="2001-05-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_vbtsql.html" adv="1" patch="1">20010327 Remote buffer overflow in DCOM VB T-SQL debugger</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-018">MS01-018</ref>
    </refs>
    <vuln_soft>
      <prod name="visual_basic" vendor="microsoft">
        <vers num="6.0" edition=":enterprise"/>
      </prod>
      <prod name="visual_studio" vendor="microsoft">
        <vers num="6.0" edition=":~~enterprise~~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0154" seq="2001-0154" published="2001-05-03" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98596775905044&amp;w=2">20010330 Incorrect MIME Header Can Cause IE to Execute E-mail Attachment</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1001197">1001197</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-06.html">CA-2001-06</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-066.shtml">L-066</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2524">2524</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-020">MS01-020</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6306">ie-mime-execute-code(6306)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A141">oval:org.mitre.oval:def:141</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0155" seq="2001-0155" published="2001-06-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a021601-1.txt">A021601-1</ref>
      <ref source="CONFIRM" url="http://www.vandyke.com/products/vshell/security102.html">http://www.vandyke.com/products/vshell/security102.html</ref>
    </refs>
    <vuln_soft>
      <prod name="vshell" vendor="van_dyke_technologies">
        <vers num="1.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0156" seq="2001-0156" published="2001-06-02" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local users to conduct arbitrary port forwarding to other systems.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a021601-1.txt" adv="1" patch="1">A021601-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2402">2402</ref>
      <ref source="CONFIRM" url="http://www.vandyke.com/products/vshell/security102.html">http://www.vandyke.com/products/vshell/security102.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6148">vshell-port-forwarding-rule(6148)</ref>
    </refs>
    <vuln_soft>
      <prod name="vshell" vendor="van_dyke_technologies">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0157" seq="2001-0157" published="2001-06-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a030101-1.txt" adv="1" patch="1">A030101-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6196">palm-debug-bypass-password(6196)</ref>
    </refs>
    <vuln_soft>
      <prod name="palm_os" vendor="palm">
        <vers num="3.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0160" seq="2001-0160" published="2001-01-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="wavelan" vendor="lucent">
        <vers num=""/>
      </prod>
      <prod name="orinoco_wavelan" vendor="orinoco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0161" seq="2001-0161" published="2001-01-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="aironet" vendor="cisco">
        <vers num="340-series"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0162" seq="2001-0162" published="2001-01-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_ce" vendor="microsoft">
        <vers num="3.0.9348"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0163" seq="2001-0163" published="2001-01-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf" adv="1">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="aironet_ap340" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0164" seq="2001-0164" published="2001-06-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a030701-1.txt" adv="1" patch="1">A030701-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6233">netscape-directory-server-bo(6233)</ref>
    </refs>
    <vuln_soft>
      <prod name="directory_server" vendor="netscape">
        <vers num="4.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0165" seq="2001-0165" published="2001-05-03" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0517.html" adv="1">20010131 [SPSadvisory#40]Solaris7/8 ximp40 shared library buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2322" adv="1">2322</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6039">solaris-ximp40-bo(6039)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0166" seq="2001-0166" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0491.html" adv="1">20001229 Shockwave Flash buffer overflow</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5826">shockwave-flash-swf-bo(5826)</ref>
    </refs>
    <vuln_soft>
      <prod name="shockwave_flash_plugin" vendor="macromedia">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0167" seq="2001-0167" published="2001-05-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AT&amp;T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98088315825366&amp;w=2">20010129 [CORE SDI ADVISORY] WinVNC client buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2305" adv="1" patch="1">2305</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6025">winvnc-client-bo(6025)</ref>
    </refs>
    <vuln_soft>
      <prod name="winvnc" vendor="att">
        <vers num="3.3.3r7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0168" seq="2001-0168" published="2001-05-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AT&amp;T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=vnc-list&amp;m=98080763005455&amp;w=2">20010129 [CORE SDI ADVISORY] WinVNC server buffer overflow</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/598581">VU#598581</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2306" adv="1" patch="1">2306</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6026">winvnc-server-bo(6026)</ref>
    </refs>
    <vuln_soft>
      <prod name="winvnc" vendor="att">
        <vers num="3.3.3r7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0169" seq="2001-0169" published="2001-03-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="TURBO" url="http://archives.neohapsis.com/archives/linux/turbolinux/2001-q1/0004.html">TLSA2000021-2</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-007.0.txt">CSSA-2001-007</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-039">DSA-039</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-012.php3?dis=7.2" adv="1" patch="1">MDKSA-2001:012</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_001_glibc_txt.html">SuSE-SA:2001:01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-002.html" adv="1" patch="1">RHSA-2001:002</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/157650" patch="1">20010121 Trustix Security Advisory - glibc</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2223" adv="1" patch="1">2223</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5971">linux-glibc-preload-overwrite(5971)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0" edition=":alpha"/>
        <vers num="6.0" edition=":i386"/>
        <vers num="6.0" edition=":sparc"/>
        <vers num="6.1" edition=":alpha"/>
        <vers num="6.1" edition=":i386"/>
        <vers num="6.1" edition=":sparc"/>
        <vers num="6.2" edition=":alpha"/>
        <vers num="6.2" edition=":i386"/>
        <vers num="6.2" edition=":sparc"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.1"/>
        <vers num="1.2"/>
      </prod>
      <prod name="turbolinux" vendor="turbolinux">
        <vers num="6.0.5" prev="1"/>
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0170" seq="2001-0170" published="2001-03-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0131.html" adv="1">20010110 Glibc Local Root Exploit</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0186.html" adv="1" patch="1">20010110 [slackware-security] glibc 2.2 local vulnerability on setuid binaries</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-001.html" adv="1" patch="1">RHSA-2001:001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2181" adv="1" patch="1">2181</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5907">linux-glibc-read-files(5907)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="7.0_beta"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="ecommerce"/>
        <vers num="graficas"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.3"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0" edition=":alpha"/>
        <vers num="7.0" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0171" seq="2001-0171" published="2001-05-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0505.html" adv="1">20010130 DOS Vulnerability in SlimServe HTTPd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2318" adv="1">2318</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6028">slimserve-httpd-dos(6028)</ref>
    </refs>
    <vuln_soft>
      <prod name="slimserve" vendor="whitsoft">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0172" seq="2001-0172" published="2001-03-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0127.html" adv="1">20010109 major security bug in reiserfs (may affect SuSE Linux)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2180" adv="1">2180</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5910">suse-reiserfs-long-filenames(5910)</ref>
    </refs>
    <vuln_soft>
      <prod name="reiserfs" vendor="hans_reiser">
        <vers num="3.5.28"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0173" seq="2001-0173" published="2001-05-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0486.html" adv="1">20010130 Nobreak Tecnologies CrazyWWWBoard Remote Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2329" adv="1" patch="1">2329</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6033">crazywwwboard-qdecoder-bo(6033)</ref>
    </refs>
    <vuln_soft>
      <prod name="crazywwwboard" vendor="nobreak_technologies">
        <vers num="3.0.1"/>
        <vers num="98"/>
        <vers num="98pe"/>
        <vers num="2000.0lepx"/>
        <vers num="2000.0px"/>
        <vers num="2000lepx"/>
        <vers num="2000px"/>
      </prod>
      <prod name="qdecoder" vendor="qdecoder">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0174" seq="2001-0174" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large "To" address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0500.html" adv="1">20010130 Security hole in Virus Buster 2001</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6034">virusbuster-mua-bo(6034)</ref>
    </refs>
    <vuln_soft>
      <prod name="virus_buster_2001" vendor="trend_micro">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0175" seq="2001-0175" published="2001-03-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98021351718874&amp;w=2">20010122 def-2001-05: Netscape Fasttrack Server Caching DoS</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98035833331446&amp;w=2">20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2273" adv="1">2273</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5985">netscape-fasttrack-cache-dos(5985)</ref>
    </refs>
    <vuln_soft>
      <prod name="fasttrack_server" vendor="netscape">
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0176" seq="2001-0176" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The setuid doroot program in Voyant Sonata 3.x executes arbitrary command line arguments, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0278.html" adv="1">20001218 More Sonata Conferencing software vulnerabilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2125" adv="1">2125</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5787">sonata-command-execute(5787)</ref>
    </refs>
    <vuln_soft>
      <prod name="sonata" vendor="voyant_technologies">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0177" seq="2001-0177" published="2001-03-26" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/155388" adv="1">20010110 Vulnerable: Conference Room Professional-Developer Edititon.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2178" adv="1" patch="1">2178</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5909">conferenceroom-developer-dos(5909)</ref>
    </refs>
    <vuln_soft>
      <prod name="conferenceroom" vendor="webmaster">
        <vers num="1.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0178" seq="2001-0178" published="2001-03-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt" adv="1" patch="1">CSSA-2001-005.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-018.php3?dis=7.2" adv="1" patch="1">MDKSA-2001:018</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_002_kdesu_txt.html">SuSE-SA:2001:02</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5995">kde2-kdesu-retrieve-passwords(5995)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="6.0"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0179" seq="2001-0179" published="2001-05-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a "."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=19546&amp;Method=Full" adv="1" patch="1">ASB01-02</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6008">jrun-webinf-file-retrieval(6008)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0180" seq="2001-0180" published="2001-05-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0471.html" adv="1" patch="1">20010129 Remote Command Execution in guestserver.cgi + exploit</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6027">guestserver-cgi-execute-commands(6027)</ref>
    </refs>
    <vuln_soft>
      <prod name="guestserver" vendor="lars_ellingsen">
        <vers num="4.12" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0181" seq="2001-0181" published="2001-03-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-003.0.txt" adv="1" patch="1">CSSA-2001-003.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2215" adv="1" patch="1">2215</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5953">dhcp-format-string(5953)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_desktop" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0182" seq="2001-0182" published="2001-03-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0298.html" adv="1">20010117 Licensing Firewall-1 DoS Attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2238" adv="1" patch="1">2238</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5966">fw1-limited-license-dos(5966)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0183" seq="2001-0183" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:08.ipfw.asc" adv="1" patch="1">FreeBSD-SA-01:08</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-029.shtml">L-029</ref>
      <ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/2001-01/0424.html">20010125 ecepass - proof of concept code for FreeBSD ipfw bypass</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2293" adv="1" patch="1">2293</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5998">ipfw-bypass-firewall(5998)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0" edition="alpha"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0184" seq="2001-0184" published="2001-03-26" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0343.html">20010121 eEye Iris the Network traffic analyser DoS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0352.html" adv="1">20010121 eEye Iris the Network traffic analyser DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2278" adv="1">2278</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5981">eeye-iris-dos(5981)</ref>
    </refs>
    <vuln_soft>
      <prod name="iris" vendor="eeye_digital_security">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0185" seq="2001-0185" published="2001-03-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/157952" adv="1">20010123 Make The Netopia R9100 Router To Crash</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2287" adv="1" patch="1">2287</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6001">netopia-telnet-dos(6001)</ref>
    </refs>
    <vuln_soft>
      <prod name="r9100_router" vendor="netopia">
        <vers num="4.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0186" seq="2001-0186" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0061.html" adv="1">20010204 Vulnerability in Free Java Web Server</ref>
    </refs>
    <vuln_soft>
      <prod name="free_java_web_server" vendor="free_java_web_server">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0187" seq="2001-0187" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000443">CLA-2001:443</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-016">DSA-016</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2296" adv="1" patch="1">2296</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6020">wuftp-debug-format-string(6020)</ref>
    </refs>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4.1"/>
        <vers num="2.4.2_beta9" edition=":academ"/>
        <vers num="2.4.2_beta18" edition=":academ"/>
        <vers num="2.4.2_beta18_vr4"/>
        <vers num="2.4.2_beta18_vr5"/>
        <vers num="2.4.2_beta18_vr6"/>
        <vers num="2.4.2_beta18_vr7"/>
        <vers num="2.4.2_beta18_vr8"/>
        <vers num="2.4.2_beta18_vr9"/>
        <vers num="2.4.2_beta18_vr10"/>
        <vers num="2.4.2_beta18_vr11"/>
        <vers num="2.4.2_beta18_vr12"/>
        <vers num="2.4.2_beta18_vr13"/>
        <vers num="2.4.2_beta18_vr14"/>
        <vers num="2.4.2_beta18_vr15"/>
        <vers num="2.4.2_vr16"/>
        <vers num="2.4.2_vr17"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0188" seq="2001-0188" published="2001-03-26" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0350.html" adv="1" patch="1">20010122 def-2001-03: GoodTech Systems FTP Connection DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2270" adv="1" patch="1">2270</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5984">goodtech-ftp-dos(5984)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_server_95_98" vendor="goodtech">
        <vers num="3.0.1"/>
      </prod>
      <prod name="ftp_server_nt_2000" vendor="goodtech">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0189" seq="2001-0189" published="2001-03-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0346.html" adv="1">20010119 LocalWEB2000 Directory Traversal Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2268" adv="1">2268</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5982">localweb2k-directory-traversal(5982)</ref>
    </refs>
    <vuln_soft>
      <prod name="localweb2000" vendor="intranet-server">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0190" seq="2001-0190" published="2001-03-26" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97983943716311&amp;w=2">20010117 Solaris /usr/bin/cu Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98028642319440&amp;w=2">20010123 Solaris /usr/bin/cu Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6224">cu-argv-bo(6224)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0191" seq="2001-0191" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0030.html" adv="1" patch="1">20010202 Remote vulnerability in gnuserv/XEmacs</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-019.php3" patch="1">MDKSA-2001:019</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-010.html" patch="1">RHSA-2001:010</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-011.html" patch="1">RHSA-2001:011</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6056">gnuserv-tcp-cookie-overflow(6056)</ref>
    </refs>
    <vuln_soft>
      <prod name="gnuserv" vendor="andy_norman">
        <vers num="3.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0192" seq="2001-0192" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0047.html">20010201 XMail CTRLServer remote buffer overflow vulnerability</ref>
      <ref source="CONFIRM" url="http://xmailserver.org/XMail-Readme.txt">http://xmailserver.org/XMail-Readme.txt</ref>
    </refs>
    <vuln_soft>
      <prod name="xmail" vendor="davide_libenzi">
        <vers num="0.66" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0193" seq="2001-0193" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98096782126481&amp;w=2">20010131 SuSe / Debian man package format string vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-028" adv="1" patch="1">DSA-028</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2327" adv="1" patch="1">2327</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6059">man-i-format-string(6059)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" edition=":68k"/>
        <vers num="2.2" edition=":alpha"/>
        <vers num="2.2" edition=":arm"/>
        <vers num="2.2" edition=":powerpc"/>
        <vers num="2.2" edition=":sparc"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0194" seq="2001-0194" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-020.php3" adv="1" patch="1">MDKSA-2001:020-1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6043">cups-httpgets-dos(6043)</ref>
    </refs>
    <vuln_soft>
      <prod name="cups" vendor="easy_software_products">
        <vers num="1.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0195" seq="2001-0195" published="2001-03-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-015" adv="1" patch="1">DSA-015</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5994">linux-sash-shadow-readable(5994)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0196" seq="2001-0196" published="2001-05-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:11.inetd.v1.1.asc">FreeBSD-SA-01:11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2324" adv="1" patch="1">2324</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6052">inetd-ident-read-files(6052)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0197" seq="2001-0197" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0348.html" adv="1" patch="1">20010121 [pkc] format bugs in icecast 1.3.8b2 and prior</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000374" patch="1">CLA-2001:374</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-004.html" patch="1">RHSA-2001:004</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2264" adv="1" patch="1">2264</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5978">icecast-format-string(5978)</ref>
    </refs>
    <vuln_soft>
      <prod name="icecast" vendor="icecast">
        <vers num="1.3.7"/>
        <vers num="1.3.8_beta2" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0198" seq="2001-0198" published="2001-05-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.6" CVSS_base_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98096678523370&amp;w=2" adv="1">20010131 [SPSadvisory#41]Apple Quick Time Plug-in Buffer Overflow</ref>
      <ref source="EXPLOIT-DB" url="http://www.exploit-db.com/exploits/20605" adv="1">20605</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2328" adv="1">2328</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6040">quicktime-embedded-tag-bo(6040)</ref>
    </refs>
    <vuln_soft>
      <prod name="quicktime" vendor="apple">
        <vers num="4.1.2" edition=":~~~windows~~:ja"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0199" seq="2001-0199" published="2001-05-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0064.html" adv="1">20010204 Vulnerability in SEDUM HTTP Server</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/651994">VU#651994</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2335" adv="1">2335</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6063">sedum-directory-traversal(6063)</ref>
    </refs>
    <vuln_soft>
      <prod name="sedum" vendor="guido_frassetto">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0200" seq="2001-0200" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0052.html" adv="1">20010204 Web root exposure in HSWeb Webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2336" adv="1">2336</ref>
    </refs>
    <vuln_soft>
      <prod name="hsweb" vendor="heat-on_software">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0201" seq="2001-0201" published="2001-03-26" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0287.html" adv="1">20010117 Postaci allows arbitrary SQL query execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2230" adv="1">2230</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5972">postaci-sql-command-injection(5972)</ref>
    </refs>
    <vuln_soft>
      <prod name="postaci" vendor="umut_gokbayrak">
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0202" seq="2001-0202" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0073.html" adv="1">20010205 Vulnerability in Picserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2339" adv="1">2339</ref>
    </refs>
    <vuln_soft>
      <prod name="picserver" vendor="informs">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0203" seq="2001-0203" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0342.html" adv="1" patch="1">20010120 Watchguard Firewall Elevated Privilege Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2284" adv="1" patch="1">2284</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5979">watchguard-firebox-obtain-passphrase(5979)</ref>
    </refs>
    <vuln_soft>
      <prod name="firebox_ii" vendor="watchguard">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0204" seq="2001-0204" published="2001-06-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/162965" adv="1" patch="1">20010214 def-2001-07: Watchguard Firebox II PPTP DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2369" adv="1" patch="1">2369</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6109">firebox-pptp-dos(6109)</ref>
    </refs>
    <vuln_soft>
      <prod name="firebox_ii" vendor="watchguard">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0205" seq="2001-0205" published="2001-05-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98148759123258&amp;w=2">20010206 Vulnerability in AOLserver</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98168216003867&amp;w=2">20010208 Vulnerability in AOLserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2343" adv="1">2343</ref>
    </refs>
    <vuln_soft>
      <prod name="aol_server" vendor="aol">
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0206" seq="2001-0206" published="2001-06-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0137.html" adv="1" patch="1">20010207 Vulnerability in Soft Lite ServerWorx</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2346" adv="1">2346</ref>
    </refs>
    <vuln_soft>
      <prod name="serverworx" vendor="soft_lite">
        <vers num="3.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0207" seq="2001-0207" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in bing allows remote attackers to execute arbitrary commands via a long hostname, which is copied to a small buffer after a reverse DNS lookup using the gethostbyaddr function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0330.html" adv="1">20010119 Buffer overflow in bing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2279" adv="1" patch="1">2279</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6036">linux-bing-bo(6036)</ref>
    </refs>
    <vuln_soft>
      <prod name="bing" vendor="pierre_beyssac">
        <vers num="1.0.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0208" seq="2001-0208" published="2001-06-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0205.html" adv="1" patch="1">20010211 Security Hole in Microfocus Cobol</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2359" adv="1" patch="1">2359</ref>
    </refs>
    <vuln_soft>
      <prod name="cobol" vendor="microfocus">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0209" seq="2001-0209" published="2001-03-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0305.html">20010118 Shoutcast Server Buffer Crashes Server</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5965">shoutcast-description-bo(5965)</ref>
    </refs>
    <vuln_soft>
      <prod name="dnas" vendor="shoutcast">
        <vers num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0210" seq="2001-0210" published="2001-06-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/162259" adv="1" patch="1">20010212 Commerce.cgi Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2361" adv="1">2361</ref>
    </refs>
    <vuln_soft>
      <prod name="commerce.cgi" vendor="carey_internet_service">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0211" seq="2001-0211" published="2001-06-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0217.html" adv="1">20010212 WebSPIRS CGI script "show files" Vulnerability.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2362" patch="1">2362</ref>
    </refs>
    <vuln_soft>
      <prod name="webspirs" vendor="silverplatter">
        <vers num="3.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0212" seq="2001-0212" published="2001-06-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0218.html" adv="1">20010212 HIS Auktion 1.62: "show files" vulnerability and remote command execute.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2367" adv="1">2367</ref>
    </refs>
    <vuln_soft>
      <prod name="auktion" vendor="his">
        <vers num="1.62"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0213" seq="2001-0213" published="2001-05-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in pi program in PlanetIntra 2.5 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0421.html" adv="1">200101125 [SAFER] Security Bulletin 010125.EXP.1.12</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6002">planetintra-pi-bo(6002)</ref>
    </refs>
    <vuln_soft>
      <prod name="planet_intra" vendor="planet_intra">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0214" seq="2001-0214" published="2001-06-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0212.html" adv="1">20010212 Way board: "show files" Vulnerability with null bite bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2370" adv="1">2370</ref>
    </refs>
    <vuln_soft>
      <prod name="way-board" vendor="way">
        <vers num="cgi"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0215" seq="2001-0215" published="2001-06-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0213.html" adv="1">20010212 ROADS search system "show files" Vulnerability with "null bite" bug</ref>
      <ref source="CONFIRM" url="http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html">http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2371" adv="1" patch="1">2371</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6097">roads-search-view-files(6097)</ref>
    </refs>
    <vuln_soft>
      <prod name="roads" vendor="martin_hamilton">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0216" seq="2001-0216" published="2001-06-02" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html" adv="1">20010212 PALS Library System "show files" Vulnerability and remote command execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2372" adv="1" patch="1">2372</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6102">webpals-library-cgi-url(6102)</ref>
    </refs>
    <vuln_soft>
      <prod name="webpals" vendor="mnscu_pals">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0217" seq="2001-0217" published="2001-06-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html" adv="1">20010212 PALS Library System "show files" Vulnerability and remote command execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2372" adv="1" patch="1">2372</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6102">webpals-library-cgi-url(6102)</ref>
    </refs>
    <vuln_soft>
      <prod name="webpals" vendor="mnscu_pals">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0218" seq="2001-0218" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0456.html" patch="1">20010126 format string vulnerability in mars_nwe 0.99pl19</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0081.html" adv="1" patch="1">FreeBSD-SA-01:20</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6019">mars-nwe-format-string(6019)</ref>
    </refs>
    <vuln_soft>
      <prod name="mars_nwe" vendor="martin_stover">
        <vers num="0.99_pl19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0219" seq="2001-0219" published="2001-03-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0016.html" patch="1">HPSBUX0101-137</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2239" adv="1" patch="1">2239</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5957">hp-stm-dos(5957)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
        <vers num="11.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0220" seq="2001-0220" published="2001-06-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0082.html" adv="1" patch="1">FreeBSD-SA-01:21</ref>
    </refs>
    <vuln_soft>
      <prod name="ja-elvis" vendor="ja-elvis">
        <vers num="1.8.4_1" prev="1"/>
      </prod>
      <prod name="ko-helvis" vendor="ko-helvis">
        <vers num="1.8h2_1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0221" seq="2001-0221" published="2001-06-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0079.html" adv="1" patch="1">FreeBSD-SA-01:19</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6073">ja-xklock-bo(6073)</ref>
    </refs>
    <vuln_soft>
      <prod name="ja-xklock" vendor="freebsd">
        <vers num="2.7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0222" seq="2001-0222" published="2001-03-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-004.0.txt" adv="1" patch="1">CSSA-2001-004.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-016.php3" patch="1">MDKSA-2001-016</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6011">linux-webmin-tmpfiles(6011)</ref>
    </refs>
    <vuln_soft>
      <prod name="webmin" vendor="webmin">
        <vers num="0.83"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0223" seq="2001-0223" published="2001-03-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in wwwwais allows remote attackers to execute arbitrary commands via a long QUERY_STRING (HTTP GET request).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97984174724339&amp;w=2">20010117 numerous holes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5980">wwwwais-cgi-dos(5980)</ref>
    </refs>
    <vuln_soft>
      <prod name="wwwwais.25.c" vendor="spawar.navy.mil">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0224" seq="2001-0224" published="2001-06-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0216.html" adv="1">20010212 Vulnerability in Muscat Empower wich can print path to DB-dir.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2374" adv="1">2374</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6093">muskat-empower-url-dir(6093)</ref>
    </refs>
    <vuln_soft>
      <prod name="muscat_empower" vendor="brightstation">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0225" seq="2001-0225" published="2001-06-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0127.html" adv="1" patch="1">20010207 Infobot 0.44.5.3/below remotely vulnerable (also in FreeBSD ports tree)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2349" adv="1">2349</ref>
    </refs>
    <vuln_soft>
      <prod name="infobot" vendor="lenzo">
        <vers num="0.44.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0226" seq="2001-0226" published="2001-05-03" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html" adv="1">20010205 Vulnerabilities in BiblioWeb Server</ref>
    </refs>
    <vuln_soft>
      <prod name="biblioweb_server" vendor="biblioscape">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0227" seq="2001-0227" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html" adv="1">20010205 Vulnerabilities in BiblioWeb Server</ref>
    </refs>
    <vuln_soft>
      <prod name="biblioweb_server" vendor="biblioscape">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0228" seq="2001-0228" published="2001-05-03" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0022.html" adv="1" patch="1">20010202 GoAhead Web Server Directory Traversal Vulnerability</ref>
      <ref source="CONFIRM" url="http://freecode.com/projects/embedthis-goahead-webserver/releases/343539">http://freecode.com/projects/embedthis-goahead-webserver/releases/343539</ref>
      <ref source="OSVDB" url="http://osvdb.org/81099">81099</ref>
    </refs>
    <vuln_soft>
      <prod name="goahead_webserver" vendor="goahead_software">
        <vers num="v.2.0"/>
        <vers num="v.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0229" seq="2001-0229" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0112.html" adv="1">20010206 Security hole in ChiliSoft ASP on Linux.</ref>
    </refs>
    <vuln_soft>
      <prod name="chilisoft" vendor="sun">
        <vers num="3.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0230" seq="2001-0230" published="2001-06-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0083.html" adv="1" patch="1">FreeBSD-SA-01:22</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6077">dc20ctrl-port-bo(6077)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="0.4_1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0231" seq="2001-0231" published="2001-03-26" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html" adv="1">20010103 News Desk 1.2 CGI Vulnerbility</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/496064">VU#496064</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2172" adv="1">2172</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5898">newsdesk-cgi-read-files(5898)</ref>
    </refs>
    <vuln_soft>
      <prod name="news_desk" vendor="ibrow">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0232" seq="2001-0232" published="2001-03-26" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html" adv="1">20010103 News Desk 1.2 CGI Vulnerbility</ref>
    </refs>
    <vuln_soft>
      <prod name="news_desk" vendor="ibrow">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0233" seq="2001-0233" published="2001-03-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:14.micq.asc" adv="1" patch="1">FreeBSD-SA-01:14</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0307.html">20010118 [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0395.html" adv="1" patch="1">20010124 patch Re: [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-012" adv="1" patch="1">DSA-012</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-005.html" patch="1">RHSA-2001:005</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5962">micq-sprintf-remote-bo(5962)</ref>
    </refs>
    <vuln_soft>
      <prod name="micq" vendor="matthew_smith">
        <vers num="0.4.6" prev="1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0234" seq="2001-0234" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0460.html" adv="1" patch="1">20010126 NewsDaemon remote administrator access</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=60570">http://sourceforge.net/forum/forum.php?forum_id=60570</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6010">newsdaemon-gain-admin-access(6010)</ref>
    </refs>
    <vuln_soft>
      <prod name="newsdaemon" vendor="sourceforge">
        <vers num="0.21b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0235" seq="2001-0235" published="2001-03-26" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:09.crontab.v1.1.asc" adv="1" patch="1">FreeBSD-SA-01:09</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-024" adv="1" patch="1">DSA-024</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2332">2332</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6225">crontab-read-files(6225)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0236" seq="2001-0236" published="2001-05-03" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98462536724454&amp;w=2">20010314 Solaris /usr/lib/dmi/snmpXdmid vulnerability</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/207">00207</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-05.html" adv="1" patch="1">CA-2001-05</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-065.shtml">L-065</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2417" adv="1">2417</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6245">solaris-snmpxdmid-bo(6245)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0237" seq="2001-0237" published="2001-06-27" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-079.shtml">L-079</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98942093221908&amp;w=2">20010509 def-2001-24: Windows 2000 Kerberos DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2707">2707</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-024">MS01-024</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6506">win2k-kerberos-dos(6506)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0238" seq="2001-0238" published="2001-07-02" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-074.shtml">L-074</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-022">MS01-022</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6405">ms-dacipp-webdav-access(6405)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_95" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0239" seq="2001-0239" published="2001-07-02" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-073.shtml">L-073</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176912" adv="1">20010416 [SX-20010320-2] - Microsoft ISA Server Denial of Service</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/177160" adv="1">20010417 [SX-20010320-2b] - Followup re. Microsoft ISA Server Denial of Service</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/179986" adv="1">20010427 Microsoft ISA Server Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2600" adv="1" patch="1">2600</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-021">MS01-021</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6383">isa-web-proxy-dos(6383)</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0240" seq="2001-0240" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2753" adv="1">2753</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-028">MS01-028</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6571" adv="1">word-rtf-macro-execution(6571)</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="97"/>
        <vers num="98" edition=":~~~mac_os_x~~"/>
        <vers num="98" edition="::ja"/>
        <vers num="2000"/>
        <vers num="2001" edition=":~~~mac_os_x~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0241" seq="2001-0241" published="2001-06-27" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98874912915948&amp;w=2">20010501 Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-10.html">CA-2001-10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2674" adv="1" patch="1">2674</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-023">MS01-023</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6485">iis-isapi-printer-bo(6485)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1068">oval:org.mitre.oval:def:1068</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0242" seq="2001-0242" published="2001-06-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/187528">VU#187528</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/181419">20010502 Microsoft Media Player ASX Parser buffer overflow vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/183906">20010506 Re: Microsoft Media Player ASX Parser buffer overflow vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2677" adv="1">2677</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2686">2686</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-029">MS01-029</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5574">mediaplayer-asx-bo(5574)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0243" seq="2001-0243" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows remote attackers to read certain files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2765">2765</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-029">MS01-029</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6584">mediaplayer-html-shortcut(6584)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="6.4"/>
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0244" seq="2001-0244" published="2001-06-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2709">2709</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-025">MS01-025</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6517">winnt-indexserver-search-bo(6517)</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0245" seq="2001-0245" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-025">MS01-025</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6518">win-indexserver-view-files(6518)</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
      <prod name="indexing_service" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0246" seq="2001-0246" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-027">MS01-027</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0247" seq="2001-0247" published="2001-06-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc" patch="1">NetBSD-SA2000-018</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010802-01-P">20010802-01-P</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0466.html" adv="1" patch="1">FreeBSD-SA-01:33</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-07.html" adv="1" patch="1">CA-2001-07</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/048.asp">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2548" adv="1" patch="1">2548</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6332">ftp-glob-expansion(6332)</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5_1.1.1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="2.2"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.8"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.1"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2m"/>
        <vers num="6.5.3"/>
        <vers num="6.5.3f"/>
        <vers num="6.5.3m"/>
        <vers num="6.5.4"/>
        <vers num="6.5.5"/>
        <vers num="6.5.6"/>
        <vers num="6.5.7"/>
        <vers num="6.5.8"/>
        <vers num="6.5.10"/>
        <vers num="6.5.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0248" seq="2001-0248" published="2001-06-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-07.html" adv="1" patch="1">CA-2001-07</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/048.asp">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2552" adv="1" patch="1">2552</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6332">ftp-glob-expansion(6332)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.30"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0249" seq="2001-0249" published="2001-06-18" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-07.html" adv="1" patch="1">CA-2001-07</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/048.asp">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2550" adv="1" patch="1">2550</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6332">ftp-glob-expansion(6332)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0250" seq="2001-0250" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0396.html" adv="1" patch="1">20010124 [SAFER] Security Bulletin 010124.EXP.1.11</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2285" adv="1" patch="1">2285</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5997">netscape-enterprise-list-directories(5997)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.0"/>
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0251" seq="2001-0251" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0422.html" adv="1" patch="1">20010125 [SAFER] Security Bulletin 010125.DOS.1.5</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2294" adv="1" patch="1">2294</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6003">netscape-enterprise-revlog-dos(6003)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_server" vendor="netscape">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0252" seq="2001-0252" published="2001-06-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98035833331446&amp;w=2">20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/157641" adv="1">20010122 def-2001-04: Netscape Enterprise Server Dot-DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2282" adv="1">2282</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5983">netscape-enterprise-dot-dos(5983)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_enterprise_server" vendor="iplanet">
        <vers num="4.1sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0253" seq="2001-0253" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0463.html" adv="1">20010128 Hyperseek 2000 Search Engine - "show directory &amp; files" bug</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/146704">VU#146704</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2314" adv="1" patch="1">2314</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6012">hyperseek-cgi-reveal-info(6012)</ref>
    </refs>
    <vuln_soft>
      <prod name="hyperseek" vendor="iweb_systems">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0254" seq="2001-0254" published="2001-06-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98021181215325&amp;w=2">20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp++_server" vendor="fastream">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0255" seq="2001-0255" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98021181215325&amp;w=2">20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2267" adv="1">2267</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5977">fastream-ftp-path-disclosure(5977)</ref>
    </refs>
    <vuln_soft>
      <prod name="fastream_ftp++_server" vendor="fastream">
        <vers num="2.0"/>
      </prod>
      <prod name="fastream_ftp_server" vendor="fastream">
        <vers num="2.0beta_11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0256" seq="2001-0256" published="2001-06-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98021181215325&amp;w=2">20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2261" adv="1">2261</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5976">fastream-ftp-server-dos(5976)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp++_server" vendor="fastream">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0257" seq="2001-0257" published="2001-06-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html" adv="1">20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2291" adv="1">2291</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5988">easycom-safecom-url-bo(5988)</ref>
    </refs>
    <vuln_soft>
      <prod name="easycom_safecom_print_server" vendor="i-data_international">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0258" seq="2001-0258" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html" adv="1">20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5989">easycom-safecom-printguide-dos(5989)</ref>
    </refs>
    <vuln_soft>
      <prod name="easycom_safecom_print_server" vendor="i-data_international">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0259" seq="2001-0259" published="2001-06-02" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0262.html" adv="1" patch="1">20010116 Bug in SSH1 secure-RPC support can expose users' private keys</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2222" adv="1" patch="1">2222</ref>
      <ref source="CONFIRM" url="http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html" adv="1">http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5963">ssh-rpc-private-key(5963)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0260" seq="2001-0260" published="2001-06-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0360.html" adv="1" patch="1">20010123 [SAFER] Security Bulletin 010123.EXP.1.10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2283" adv="1" patch="1">2283</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5993">lotus-domino-smtp-bo(5993)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_mail_server" vendor="lotus">
        <vers num="5.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0261" seq="2001-0261" published="2001-06-02" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97992179925715&amp;w=2">20010119 BugTraq: EFS Win 2000 flaw</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98027311214976&amp;w=2">20010123 Reply to EFS note on Bugtraq</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2243" adv="1">2243</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5973">win2k-efs-recover-data(5973)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0262" seq="2001-0262" published="2001-07-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a041301-1.txt" adv="1" patch="1">A041301-1</ref>
    </refs>
    <vuln_soft>
      <prod name="smartdownload" vendor="netscape">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0263" seq="2001-0263" published="2001-06-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a040301-1.txt">A040301-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2537">2537</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6330">bpftp-obtain-credentials(6330)</ref>
    </refs>
    <vuln_soft>
      <prod name="g6_ftp_server" vendor="gene6">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0264" seq="2001-0264" published="2001-06-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a040301-1.txt" adv="1" patch="1">A040301-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2534" adv="1" patch="1">2534</ref>
    </refs>
    <vuln_soft>
      <prod name="g6_ftp_server" vendor="gene6">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0265" seq="2001-0265" published="2001-06-18" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a040901-1.txt" adv="1" patch="1">A040901-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2556">2556</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6643">pgp-armor-code-execution(6643)</ref>
    </refs>
    <vuln_soft>
      <prod name="pgp" vendor="pgp">
        <vers num="5"/>
        <vers num="7.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0266" seq="2001-0266" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0069.html">HPSBUX0102-143</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0267" seq="2001-0267" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0050.html" adv="1" patch="1">HPSBMP0102-008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6226">hp-nmdebug-gain-privileges(6226)</ref>
    </refs>
    <vuln_soft>
      <prod name="mpe_ix" vendor="hp">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0268" seq="2001-0268" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0353.html">20010219 Re: your mail</ref>
      <ref source="CALDERA" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q4/0014.html">CSSA-2001-SCO.35</ref>
      <ref source="NETBSD" url="http://archives.neohapsis.com/archives/netbsd/2001-q1/0093.html" adv="1" patch="1">NetBSD-SA:2001-002</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/358960">VU#358960</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata.html#userldt">20010302 The USER_LDT kernel option allows an attacker to gain access to privileged areas of kernel memory.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2739">2739</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6222">user-ldt-validation(6222)</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5" prev="1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0269" seq="2001-0269" published="2001-05-03" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0344.html" adv="1" patch="1">20010217 Solaris 8 pam_ldap.so.1 module broken</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6440">solaris-pamldap-bypass-authentication(6440)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0270" seq="2001-0270" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0349.html" adv="1" patch="1">20010219 Denial of Service Condition exists in Fore/Marconi ASX Switches</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2400" adv="1" patch="1">2400</ref>
    </refs>
    <vuln_soft>
      <prod name="forethought" vendor="marconi">
        <vers num="6.2"/>
      </prod>
      <prod name="asx-1000" vendor="marconi">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0271" seq="2001-0271" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0347.html" adv="1">20010218 mailnews.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2391">2391</ref>
    </refs>
    <vuln_soft>
      <prod name="mailnews.cgi" vendor="mailnews.cgi">
        <vers num="1.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0272" seq="2001-0272" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0259.html" adv="1" patch="1">20010212 W3.ORG sendtemp.pl</ref>
    </refs>
    <vuln_soft>
      <prod name="sendtemp.pl" vendor="w3.org">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0273" seq="2001-0273" published="2001-05-03" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0367.html" adv="1" patch="1">20010220 [CryptNET Advisory] pgp4pine-1.75-6 - expired public keys</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/566640" adv="1">VU#566640</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2405">2405</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6135">pgp4pine-expired-keys(6135)</ref>
    </refs>
    <vuln_soft>
      <prod name="pgp4pine" vendor="holger_lamm">
        <vers num="1.75.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0274" seq="2001-0274" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0276.html" adv="1" patch="1">20010214 Security hole in kicq</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0536.html" adv="1" patch="1">20010303 Re: Security hole in kicq</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6112">kicq-execute-commands(6112)</ref>
    </refs>
    <vuln_soft>
      <prod name="kicq" vendor="kicq">
        <vers num="1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0275" seq="2001-0275" published="2001-05-03" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0346.html" adv="1">20010219 NetSuite 1.02 web server vulnerabilty</ref>
    </refs>
    <vuln_soft>
      <prod name="netsuite_web_server" vendor="moby">
        <vers num="1.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0276" seq="2001-0276" published="2001-05-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98263019502565&amp;w=2">20010217 BadBlue Web Server Ext.dll Vulnerabilities</ref>
      <ref source="CONFIRM" url="http://www.badblue.com/p010219.htm">http://www.badblue.com/p010219.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2390" adv="1" patch="1">2390</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6130">badblue-ext-reveal-path(6130)</ref>
    </refs>
    <vuln_soft>
      <prod name="badblue" vendor="working_resources_inc.">
        <vers num="1.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0277" seq="2001-0277" published="2001-05-03" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98263019502565&amp;w=2">20010217 BadBlue Web Server Ext.dll Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2392" adv="1" patch="1">2392</ref>
    </refs>
    <vuln_soft>
      <prod name="badblue" vendor="working_resources_inc.">
        <vers num="1.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0278" seq="2001-0278" published="2001-05-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0050.html" adv="1" patch="1">HPSBMP0102-009</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6223">hp-linkeditor-gain-privileges(6223)</ref>
    </refs>
    <vuln_soft>
      <prod name="mpe_ix" vendor="hp">
        <vers num="6.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0279" seq="2001-0279" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0414.html" patch="1">20010222 Sudo version 1.6.3p6 now available (fwd)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0427.html">20010226 Trustix Security Advisory - sudo</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0437.html">20010225 [slackware-security] buffer overflow in sudo fixed</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000381">CLA-2001:381</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-031" adv="1" patch="1">DSA-031</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-024.php3" adv="1" patch="1">MDKSA-2001:024</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-018.html">RHSA-2001:018</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-019.html">RHSA-2001:019</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0280" seq="2001-0280" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0413.html" adv="1">20010223 Mercur Mailserver 3.3 buffer overflow with EXPN</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6149">mercur-expn-bo(6149)</ref>
    </refs>
    <vuln_soft>
      <prod name="mercur" vendor="atrium_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0281" seq="2001-0281" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0379.html" adv="1">20010221 NT drivers are potentially vulnerable to format string bug</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0282" seq="2001-0282" published="2001-05-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SEDUM 2.1 HTTP server allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0419.html" adv="1">20010223 SEDUM v2.1 HTTPd - Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod name="sedum" vendor="guido_frassetto">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0283" seq="2001-0283" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0523.html" adv="1">20010302 Sunftp build9(1) - ftp server Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="sun_ftp" vendor="sun">
        <vers num="build_9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0284" seq="2001-0284" published="2001-05-03" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata.html#ipsec_ah">20010302 Insufficient checks in the IPSEC AH IPv4 option handling code can lead to a buffer overrun in the kernel.</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0285" seq="2001-0285" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html" adv="1">20010226 A1 Server v1.0a HTTPd (DoS &amp; Dir Traversal)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="a1webserver">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0286" seq="2001-0286" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html" adv="1">20010226 A1 Server v1.0a HTTPd (DoS &amp; Dir Traversal)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="a1webserver">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0287" seq="2001-0287" published="2001-05-03" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows local users to cause a denial of service (system panic) via the -L option to the lltstat command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0528.html" adv="1">20010302 Option to VERITAS Cluster Server (VCS) lltstat command will panic system.</ref>
      <ref source="CONFIRM" url="http://seer.support.veritas.com/docs/234326.htm" adv="1">http://seer.support.veritas.com/docs/234326.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="cluster_server" vendor="symantec_veritas">
        <vers num="1.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0288" seq="2001-0288" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/ios-tcp-isn-random-pub.shtml" adv="1" patch="1">20010228 Cisco IOS Software TCP Initial Sequence Number Randomization Improvements</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0289" seq="2001-0289" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.html" adv="1" patch="1">20010228 Joe's Own Editor File Handling Error</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-041" adv="1" patch="1">DSA-041</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-026.php3" adv="1" patch="1">MDKSA-2001:026</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-024.html">RHSA-2001:024</ref>
    </refs>
    <vuln_soft>
      <prod name="joe" vendor="joseph_allen">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0290" seq="2001-0290" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0031.html" adv="1">20010306 [Mailman-Announce] ANNOUNCE Mailman 2.0.2 (important privacy patch)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="2.0.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0291" seq="2001-0291" published="2001-05-03" modified="2005-10-20" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0003.html" adv="1">20010305 Remote buffer overflow condition in post-query (CGI).</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2001-0292" seq="2001-0292" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0525.html" adv="1">20010302 PHPNUKE4.4.1a Advisory</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="4.4.1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0293" seq="2001-0293" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0508.html" adv="1">20010228 Vulnerability in FtpXQ Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2426" adv="1">2426</ref>
    </refs>
    <vuln_soft>
      <prod name="ftpxq" vendor="datawizard">
        <vers num="2.0.93"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0294" seq="2001-0294" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0511.html" adv="1">20010228 Vulnerability in TYPSoft FTP Server</ref>
    </refs>
    <vuln_soft>
      <prod name="typsoft_ftp_server" vendor="typsoft">
        <vers num="0.85"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0295" seq="2001-0295" published="2001-05-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98390925726814&amp;w=2">20010306 Warftp 1.67b04 Directory Traversal</ref>
      <ref source="CONFIRM" url="http://support.jgaa.com/?cmd=ShowArticle&amp;ID=31">http://support.jgaa.com/?cmd=ShowArticle&amp;ID=31</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2444" adv="1" patch="1">2444</ref>
    </refs>
    <vuln_soft>
      <prod name="war_ftpd" vendor="jarle_aase">
        <vers num="1.67b04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0296" seq="2001-0296" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0531.html" adv="1">20010303 WFTPD Pro 3.00 R1 Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd_pro" vendor="texas_imperial_software">
        <vers num="3.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0297" seq="2001-0297" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/165523" adv="1">20010224 The Simple Server HTTPd Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2415" adv="1">2415</ref>
    </refs>
    <vuln_soft>
      <prod name="simple_server" vendor="dattaraj_rao">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0298" seq="2001-0298" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/165671">20010227 WebReflex 1.55 HTTPd DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2425" adv="1">2425</ref>
    </refs>
    <vuln_soft>
      <prod name="webreflex" vendor="sapio_design_ltd">
        <vers num="1.55"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0299" seq="2001-0299" published="2001-06-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97535202912588&amp;w=2">20001127 Nokia firewalls</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97603879517777&amp;w=2">20001205 Nokia firewalls - Response from Nokia</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2054" adv="1" patch="1">2054</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5640">nokia-ip440-bo(5640)</ref>
    </refs>
    <vuln_soft>
      <prod name="ip440_firewall_vpn_appliance" vendor="nokia">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0300" seq="2001-0300" published="2001-06-02" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0434.html" adv="1" patch="1">20001222 vulnerability #2 in Oracle Internet Directory 2.1.1.1 in Oracle 8.1.7</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/610904">VU#610904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5804">oracle-oidldap-write-permission(5804)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_directory" vendor="oracle">
        <vers num="2.1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0301" seq="2001-0301" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0264.html" adv="1" patch="1">20010213 Security advisory for analog</ref>
      <ref source="REDHAT" url="http://archives.neohapsis.com/archives/linux/redhat/2001-q1/0056.html" adv="1" patch="1">RHSA-2001:017</ref>
      <ref source="CONFIRM" url="http://www.analog.cx/security2.html" adv="1" patch="1">http://www.analog.cx/security2.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-033" adv="1" patch="1">DSA-033</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2377" adv="1" patch="1">2377</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6105">analog-alias-bo(6105)</ref>
    </refs>
    <vuln_soft>
      <prod name="analog" vendor="stephen_turner">
        <vers num="4.15" prev="1"/>
        <vers num="4.90_beta2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0302" seq="2001-0302" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html" adv="1">20010215 Vulnerabilities in Pi3Web Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2381" adv="1" patch="1">2381</ref>
    </refs>
    <vuln_soft>
      <prod name="pi3web" vendor="pi3">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0303" seq="2001-0303" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html" adv="1">20010215 Vulnerabilities in Pi3Web Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2381" adv="1" patch="1">2381</ref>
    </refs>
    <vuln_soft>
      <prod name="pi3web" vendor="pi3">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0304" seq="2001-0304" published="2001-05-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98229372610440&amp;w=2">20010216 Vulnerability in Resin Webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2384" adv="1" patch="1">2384</ref>
    </refs>
    <vuln_soft>
      <prod name="resin" vendor="caucho_technology">
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0305" seq="2001-0305" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0324.html" adv="1">20010216 Thinking Arts Store.cgi Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2385" adv="1">2385</ref>
    </refs>
    <vuln_soft>
      <prod name="es.one" vendor="thinking_arts">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0306" seq="2001-0306" published="2001-05-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0332.html" adv="1">20010216 WEBactive HTTP Server 1.0 Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2386" adv="1">2386</ref>
    </refs>
    <vuln_soft>
      <prod name="webactive" vendor="itafrica">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0307" seq="2001-0307" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html" adv="1" patch="1">20010216 Vulnerabilities in Bajie Http JServer</ref>
      <ref source="CONFIRM" url="http://www.geocities.com/gzhangx/websrv/docs/security.html">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
    </refs>
    <vuln_soft>
      <prod name="java_http_server" vendor="bajie">
        <vers num="0.79" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0308" seq="2001-0308" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html" adv="1">20010216 Vulnerabilities in Bajie Http JServer</ref>
      <ref source="CONFIRM" url="http://www.geocities.com/gzhangx/websrv/docs/security.html">http://www.geocities.com/gzhangx/websrv/docs/security.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2388" adv="1">2388</ref>
    </refs>
    <vuln_soft>
      <prod name="java_http_server" vendor="bajie">
        <vers num="0.79" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0309" seq="2001-0309" published="2001-06-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-006.html" adv="1" patch="1">RHSA-2001:006</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6380">inetd-internal-socket-dos(6380)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0310" seq="2001-0310" published="2001-06-02" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:13.sort.asc">FreeBSD-SA-01:13</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3960">3960</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6038">sort-temp-file-abort(6038)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5.1"/>
        <vers num="4.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0311" seq="2001-0311" published="2001-06-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HPBUG" url="http://archives.neohapsis.com/archives/hp/2001-q1/0022.html">PHSS_22914</ref>
      <ref source="HPBUG" url="http://archives.neohapsis.com/archives/hp/2001-q1/0023.html">PHSS_22915</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0102-142">HPSBUX0102-142</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6434">omniback-unauthorized-access(6434)</ref>
    </refs>
    <vuln_soft>
      <prod name="omniback_ii" vendor="hp">
        <vers num="a.03.50"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0312" seq="2001-0312" published="2001-06-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0446.html" adv="1" patch="1">20010125 Yet Another IBM WebSphere Showcode Vulerability</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_plugin" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0313" seq="2001-0313" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98053139231392&amp;w=2">20010126 Borderware v6.1.2 ping DoS vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6004">borderware-ping-dos(6004)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall_server" vendor="borderware">
        <vers num="6.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0314" seq="2001-0314" published="2001-06-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98053366805491&amp;w=2">20010125 America Online 5.0 contains a buffer overflow</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6009">aol-malformed-url-dos(6009)</ref>
    </refs>
    <vuln_soft>
      <prod name="aol_server" vendor="aol">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0315" seq="2001-0315" published="2001-06-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98053777917287&amp;w=2">20010125 mIRC allows password protection to be bypassed</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6013">mirc-bypass-password(6013)</ref>
    </refs>
    <vuln_soft>
      <prod name="mirc" vendor="khaled_mardam-bey">
        <vers num="5.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0316" seq="2001-0316" published="2001-05-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html" adv="1" patch="1">20010213 Trustix Security Advisory - proftpd, kernel</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt" adv="1" patch="1">CSSA-2001-009</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-013.html">RHSA-2001:013</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2364">2364</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6079">linux-sysctl-read-memory(6079)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0317" seq="2001-0317" published="2001-05-03" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html" adv="1" patch="1">20010213 Trustix Security Advisory - proftpd, kernel</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt" adv="1" patch="1">CSSA-2001-009</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-013.html">RHSA-2001:013</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6080">linux-ptrace-modify-process(6080)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
        <vers num="2.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0318" seq="2001-0318" published="2001-06-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0117.html" adv="1" patch="1">20010206 Response to ProFTPD issues</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000380">CLA-2001:380</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97916525715657&amp;w=2">20010110 proftpd 1.2.0rc2 -- example of bad coding</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-029" adv="1" patch="1">DSA-029</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3" adv="1" patch="1">MDKSA-2001:021</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6433">proftpd-format-string(6433)</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2.0_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0319" seq="2001-0319" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0072.html" adv="1">20010205 IBM NetCommerce Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2350">2350</ref>
      <ref source="CONFIRM" url="http://www-4.ibm.com/software/webservers/commerce/netcomletter.html" adv="1">http://www-4.ibm.com/software/webservers/commerce/netcomletter.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6067">ibm-netcommerce-reveal-information(6067)</ref>
    </refs>
    <vuln_soft>
      <prod name="net.commerce" vendor="ibm">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.1" edition=":pro"/>
        <vers num="3.1" edition=":start"/>
        <vers num="3.1.1" edition=":pro"/>
        <vers num="3.1.1" edition=":start"/>
        <vers num="3.1.2" edition=":pro"/>
        <vers num="3.1.2" edition=":start"/>
        <vers num="3.2" edition=":pro"/>
        <vers num="3.2" edition=":start"/>
      </prod>
      <prod name="net.commerce_hosting_server" vendor="ibm">
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2"/>
      </prod>
      <prod name="websphere_commerce_suite" vendor="ibm">
        <vers num="3.1.2" edition=":service_provider"/>
        <vers num="3.2" edition=":service_provider"/>
        <vers num="4.1" edition=":marketplace"/>
        <vers num="4.1" edition=":pro"/>
        <vers num="4.1" edition=":start"/>
        <vers num="4.1.1" edition=":pro"/>
        <vers num="4.1.1" edition=":start"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0320" seq="2001-0320" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0425.html" adv="1">20010223 Yet another hole in PHP-Nuke</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="4.0.4"/>
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0321" seq="2001-0321" published="2001-05-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0214.html" adv="1">20010212 Fwd: Re: phpnuke, security problem...</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6512">phpnuke-opendir-read-files(6512)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="8.0_final"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0322" seq="2001-0322" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97958685100219&amp;w=2">20010115 Stack Overflow in MSHTML.DLL</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2202" adv="1">2202</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5938">ie-mshtml-dos(5938)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="outlook" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0323" seq="2001-0323" published="2001-06-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97958349623450&amp;w=2">20010115 ICMP fragmentation required but DF set problems.</ref>
      <ref source="MANDRIVA" url="http://www.mandriva.com/security/advisories?name=MDVSA-2013:150">MDVSA-2013:150</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html">http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5975">icmp-pmtu-dos(5975)</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2001-0324" seq="2001-0324" published="2001-05-03" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/win2ksecadvice/2001-q1/0060.html" adv="1">20010206 Windows client UDP exhaustion denial of service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2340" adv="1">2340</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0325" seq="2001-0325" published="2001-05-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0031.html" adv="1">20010202 QNX RTP ftpd stack overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2342" adv="1">2342</ref>
    </refs>
    <vuln_soft>
      <prod name="rtp" vendor="qnx">
        <vers num="5.60"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0326" seq="2001-0326" published="2001-05-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the &lt;&lt;ALL FILES>> FilePermission.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0255.html" adv="1" patch="1">20010212 Solution for Potential Vunerability in Granting FilePermission to Oracle Java Virtual Machine</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6438">oracle-jvm-file-permissions(6438)</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="release_1.0.2.0.1"/>
      </prod>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.7_r3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0327" seq="2001-0327" published="2001-07-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a041601-1.txt" adv="1" patch="1">A041601-1</ref>
      <ref source="CONFIRM" url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html">http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/276767">VU#276767</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="iplanet">
        <vers num="4.1_enterprise" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0328" seq="2001-0328" published="2001-06-27" modified="2017-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030201-01-P">20030201-01-P</ref>
      <ref source="SREASON" url="http://securityreason.com/securityalert/57">57</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-09.html" adv="1" patch="1">CA-2001-09</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2682">2682</ref>
      <ref source="SECTRACK" url="http://www.securitytracker.com/id/1033181">1033181</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4922">oval:org.mitre.oval:def:4922</ref>
    </refs>
  </entry>
  <entry type="CVE" name="CVE-2001-0329" seq="2001-0329" published="2001-06-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a043001-1.txt" adv="1" patch="1">A043001-1</ref>
      <ref source="CONFIRM" url="http://www.mozilla.org/projects/bugzilla/security2_12.html">http://www.mozilla.org/projects/bugzilla/security2_12.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/1199">1199</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0330" seq="2001-0330" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a043001-1.txt" adv="1" patch="1">A043001-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2671" adv="1" patch="1">2671</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6489">bugzilla-gobalpl-gain-information(6489)</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0331" seq="2001-0331" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P">20010501-01-P</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258632">VU#258632</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2714">2714</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise76.php" adv="1">20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6502">irix-espd-bo(6502)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.5"/>
        <vers num="6.5.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0332" seq="2001-0332" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98609031517525&amp;w=2">20010330 Security bug in Internet Explorer - MSScriptControl.ScriptControl</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-027">MS01-027</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0333" seq="2001-0333" published="2001-06-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98992056521300&amp;w=2">20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-12.html">CA-2001-12</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2708">2708</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026">MS01-026</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6534">iis-url-decoding(6534)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1018">oval:org.mitre.oval:def:1018</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1051">oval:org.mitre.oval:def:1051</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A37">oval:org.mitre.oval:def:37</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A78">oval:org.mitre.oval:def:78</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0334" seq="2001-0334" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026">MS01-026</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6535">iis-ftp-wildcard-dos(6535)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0335" seq="2001-0335" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2719">2719</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026">MS01-026</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6545">iis-ftp-domain-authentication(6545)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0336" seq="2001-0336" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026">MS01-026</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6858">iis-crosssitescripting-patch-dos(6858)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0337" seq="2001-0337" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026">MS01-026</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0338" seq="2001-0338" published="2001-06-27" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-087.shtml">L-087</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2735">2735</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-027">MS01-027</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6555">ie-crl-certificate-spoofing(6555)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0339" seq="2001-0339" published="2001-06-27" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-087.shtml">L-087</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2737">2737</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-027">MS01-027</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6556">ie-html-url-spoofing(6556)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1096">oval:org.mitre.oval:def:1096</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0340" seq="2001-0340" published="2001-07-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-091.shtml">L-091</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-030">MS01-030</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6652">exchange-owa-script-execution(6652)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0341" seq="2001-0341" published="2001-07-21" modified="2019-04-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99348216322147&amp;w=2">20010625 NSFOCUS SA2001-03 : Microsoft FrontPage 2000 Server Extensions Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2906" adv="1" patch="1">2906</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-035">MS01-035</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6730">frontpage-ext-rad-bo(6730)</ref>
    </refs>
    <vuln_soft>
      <prod name="frontpage_server_extensions" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0344" seq="2001-0344" published="2001-07-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-095.shtml">L-095</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-032">MS01-032</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6684">mssql-cached-connection-access(6684)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A71">oval:org.mitre.oval:def:71</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0345" seq="2001-0345" published="2001-07-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2843">2843</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031">MS01-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6667">win2k-telnet-idle-sessions-dos(6667)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0346" seq="2001-0346" published="2001-07-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031">MS01-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6668">win2k-telnet-handle-leak-dos(6668)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0347" seq="2001-0347" published="2001-07-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-092.shtml">L-092</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2847">2847</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031">MS01-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6665">win2k-telnet-domain-authentication(6665)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0348" seq="2001-0348" published="2001-07-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_mstelnet.html">20010608 Range checking fault condition in Microsoft Windows 2000 Telnet server</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-092.shtml">L-092</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2838">2838</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031">MS01-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6666">win2k-telnet-username-dos(6666)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0349" seq="2001-0349" published="2001-07-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/587587">VU#587587</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2849">2849</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031">MS01-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6664">win2k-telnet-pipe-privileges(6664)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0350" seq="2001-0350" published="2001-07-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031">MS01-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6664">win2k-telnet-pipe-privileges(6664)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0351" seq="2001-0351" published="2001-07-21" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-092.shtml">L-092</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2846">2846</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031">MS01-031</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6669">win2k-telnet-system-call-dos(6669)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0352" seq="2001-0352" published="2001-07-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="41x1_access_point" vendor="symbol">
        <vers num=""/>
      </prod>
      <prod name="3crwe747a" vendor="3com">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0353" seq="2001-0353" published="2001-07-21" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/206">00206</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-15.html">CA-2001-15</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2894">2894</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise80.php" adv="1" patch="1">20010619 Remote Buffer Overflow Vulnerability in Solaris Print Protocol Daemon</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6718">solaris-lpd-bo(6718)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0354" seq="2001-0354" published="2001-07-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/178061" adv="1">20010420 CheckBO Win9x memo overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2634" adv="1">2634</ref>
    </refs>
    <vuln_soft>
      <prod name="checkbo" vendor="thenet">
        <vers num="1.56"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0355" seq="2001-0355" published="2001-06-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98185226715517&amp;w=2">20010210 Novell Groupwise Client Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0357" seq="2001-0357" published="2001-08-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98433523520344&amp;w=2">20010310 CORRECTION to CODE: FormMail.pl can be used to send anonymous email</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6242">formmail-anonymous-flooding(6242)</ref>
    </refs>
    <vuln_soft>
      <prod name="formmail" vendor="matt_wright">
        <vers num="1.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0358" seq="2001-0358" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html" adv="1">20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6218">halflife-map-bo(6218)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6221">halflife-config-file-bo(6221)</ref>
    </refs>
    <vuln_soft>
      <prod name="half-life" vendor="sierra">
        <vers num="1573" prev="1"/>
      </prod>
      <prod name="half-life" vendor="valve_software">
        <vers num="1573" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0359" seq="2001-0359" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html" adv="1">20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6220">halflife-map-format-string(6220)</ref>
    </refs>
    <vuln_soft>
      <prod name="half-life" vendor="sierra">
        <vers num="1573" prev="1"/>
      </prod>
      <prod name="half-life_dedicated_server" vendor="valve_software">
        <vers num="1573" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0360" seq="2001-0360" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html" adv="1">20010311 Ikonboard v2.1.7b "show files" vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2471" adv="1" patch="1">2471</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6216">ikonboard-cgi-read-files(6216)</ref>
    </refs>
    <vuln_soft>
      <prod name="ikonboard" vendor="ikonboard.com">
        <vers num="2.1.7b" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0361" seq="2001-0361" published="2001-06-27" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.0" CVSS_base_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc">FreeBSD-SA-01:24</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98158450021686&amp;w=2">20010207 [CORE SDI ADVISORY] SSH1 session key recovery vulnerability</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-047.shtml">L-047</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-023">DSA-023</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-027">DSA-027</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-086">DSA-086</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv004_ssh.html">SuSE-SA:2001:04</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2344" adv="1" patch="1">2344</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6082">ssh-session-key-recovery(6082)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="1.2.3"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
      </prod>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.31" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0364" seq="2001-0364" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98467799732241&amp;w=2">20010315 Remote DoS attack against SSH Secure Shell for Windows Servers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2477" adv="1">2477</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6241">ssh-ssheloop-dos(6241)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh2" vendor="ssh">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0365" seq="2001-0365" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98503741910995&amp;w=2">20010318 feeble.you!dora.exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2490" adv="1" patch="1">2490</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6262">eudora-html-execute-code(6262)</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="5.0.2"/>
        <vers num="5.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0366" seq="2001-0366" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol">ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/180498" adv="1" patch="1">20010429 SAP R/3 Web Application Server Demo for Linux: root exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2662" adv="1" patch="1">2662</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6487">linux-sap-execute-code(6487)</ref>
    </refs>
    <vuln_soft>
      <prod name="sap_r_3_web_application_server_demo" vendor="sap">
        <vers num="1.5" prev="1"/>
      </prod>
      <prod name="saposcol" vendor="sap">
        <vers num="1.0" edition=":linux"/>
        <vers num="1.1" edition=":linux"/>
        <vers num="1.2" edition=":linux"/>
        <vers num="1.3" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0367" seq="2001-0367" published="2001-06-27" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a remote attacker to create a denial of service via HTTP URL requests containing a large number of % characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98847544303438&amp;w=2">20010428 Mirabilis ICQ WebFront Plug-in Denial of Service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2664" adv="1">2664</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="2000.0b_build3278"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0368" seq="2001-0368" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BearShare 2.2.2 and earlier allows a remote attacker to read certain files via a URL containing a series of . characters, a variation of the .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/180644" adv="1" patch="1">20010430 A Serious Security Vulnerability Found in BearShare (Directory Traversal)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2672" adv="1" patch="1">2672</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6481">bearshare-dot-download-files(6481)</ref>
    </refs>
    <vuln_soft>
      <prod name="bearshare" vendor="free_peers">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0369" seq="2001-0369" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98511407131984&amp;w=2">20010319 DGUX lpsched buffer overflow</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6258">dgux-lpsched-bo(6258)</ref>
    </refs>
    <vuln_soft>
      <prod name="unix" vendor="digital">
        <vers num="mu02"/>
        <vers num="r4.20mu06"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0370" seq="2001-0370" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98521301510554&amp;w=2">20010320 fcheck prior to 2.07.59 - vulnerability - improper use of perl 'magic open'</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6256">fcheck-open-execute-commands(6256)</ref>
    </refs>
    <vuln_soft>
      <prod name="fcheck" vendor="michael_a._gumienny">
        <vers num="2.57.59" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0371" seq="2001-0371" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-03/0403.html" adv="1" patch="1">FreeBSD-SA-01:30</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6268">ufs-ext2fs-data-disclosure(6268)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0372" seq="2001-0372" published="2001-06-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0337.html" adv="1" patch="1">20010323 FW: Akopia Interchange E-commerce Package Demo Files Vulnerability</ref>
      <ref source="CONFIRM" url="http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html">http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2499" adv="1" patch="1">2499</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6273">akopia-interchange-gain-access(6273)</ref>
    </refs>
    <vuln_soft>
      <prod name="akopia_interchange" vendor="akopia">
        <vers num="4.5.3"/>
        <vers num="4.6.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0373" seq="2001-0373" published="2001-06-18" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0336.html">20010323 NT crash dump files insecure by default</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2501" adv="1" patch="1">2501</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6275">win-userdmp-insecure-permission(6275)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0374" seq="2001-0374" published="2001-06-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q1/0779.html" adv="1">20010322 Compaq Insight Manager Proxy Vuln</ref>
      <ref source="COMPAQ" url="http://www.compaq.com/products/servers/management/mgtsw-advisory.html" adv="1" patch="1">SSRT0715</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6264">compaq-wbm-bypass-proxy(6264)</ref>
    </refs>
    <vuln_soft>
      <prod name="web-enabled_management" vendor="compaq">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0375" seq="2001-0375" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98658271707833&amp;w=2">20010406 PIX Firewall 5.1 DoS Vulnerability</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/pixfirewall-authen-flood-pub.shtml">20011003 Cisco PIX Firewall Authentication Denial of Service Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2551" adv="1" patch="1">2551</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6353">cisco-pix-tacacs-dos(6353)</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall_515" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="pix_firewall_520" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0376" seq="2001-0376" published="2001-06-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys.  This allows a remote attacker to brute force attack the pre-shared keys with significantly less resources than if the full 128 byte IKE pre-shared keys were used.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0403.html" adv="1" patch="1">20010327 SonicWall IKE pre-shared key length bug and security concern</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6304">sonicwall-ike-shared-keys(6304)</ref>
    </refs>
    <vuln_soft>
      <prod name="soho2" vendor="sonicwall">
        <vers num="6.0.0"/>
      </prod>
      <prod name="tele2" vendor="sonicwall">
        <vers num="6.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0377" seq="2001-0377" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Infradig Inframail prior to 3.98a allows a remote attacker to create a denial of service via a malformed POST request which includes a space followed by a large string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0428.html" adv="1" patch="1">20010328 Inframail Denial of Service Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6297">inframail-post-dos(6297)</ref>
    </refs>
    <vuln_soft>
      <prod name="inframail" vendor="infradig">
        <vers num="3.97a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0378" seq="2001-0378" published="2001-06-27" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/024_readline.patch" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/024_readline.patch</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6586">bsd-readline-permissions(6586)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0379" seq="2001-0379" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0101.html" adv="1" patch="1">HPSBUX0103-147</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/249224">VU#249224</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6282">hp-newgrp-additional-privileges(6282)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0380" seq="2001-0380" published="2001-06-18" modified="2017-10-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0364.html" adv="1">200103 ILMI community in olicom/crosscomm routers</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5718">oval:org.mitre.oval:def:5718</ref>
    </refs>
    <vuln_soft>
      <prod name="xlt-f" vendor="crosscom_olicom">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0381" seq="2001-0381" published="2001-06-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-017.0.txt">CSSA-2001-017.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0252.html" adv="1">20010319 Have they found a serious PGP vulnerability?!</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0274.html" adv="1">20010320 Yes, they have found a serious PGP vulnerability...sort of</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0311.html" adv="1">20010322 Re: Yes, they have found a serious PGP vulnerability...sort of</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-063.html">RHSA-2001:063</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2673">2673</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6558">openpgp-private-key-disclosure(6558)</ref>
    </refs>
    <vuln_soft>
      <prod name="openpgp" vendor="pgp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0382" seq="2001-0382" published="2001-06-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2001-q2/0001.html" adv="1" patch="1">20010327 CA CCC\Harvest exploit</ref>
    </refs>
    <vuln_soft>
      <prod name="ccc_harvest" vendor="ca">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0383" seq="2001-0383" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0017.html" adv="1">20010401 Php-nuke exploit...</ref>
      <ref source="CONFIRM" url="http://phpnuke.org/download.php?dcategory=Fixes">http://phpnuke.org/download.php?dcategory=Fixes</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2544">2544</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6342">php-nuke-url-redirect(6342)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="4.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0384" seq="2001-0384" published="2001-07-02" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176709">20010414 Re: Reliant Unix 5.43 / 5.44 ICMP port unreachable problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2606" adv="1">2606</ref>
    </refs>
    <vuln_soft>
      <prod name="reliant_unix" vendor="siemens">
        <vers num="5.45" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0385" seq="2001-0385" published="2001-07-02" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0281.html" adv="1">20010417 Advisory for GoAhead Webserver v2.1</ref>
      <ref source="CONFIRM" url="http://freecode.com/projects/embedthis-goahead-webserver/releases/343539">http://freecode.com/projects/embedthis-goahead-webserver/releases/343539</ref>
      <ref source="OSVDB" url="http://osvdb.org/81099">81099</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2607" adv="1">2607</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6400">goahead-aux-dos(6400)</ref>
    </refs>
    <vuln_soft>
      <prod name="goahead_webserver" vendor="goahead_software">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0386" seq="2001-0386" published="2001-07-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/177156" adv="1">20010417 Advisory for SimpleServer:WWW (analogX)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2608" adv="1" patch="1">2608</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6395">analogx-simpleserver-aux-dos(6395)</ref>
    </refs>
    <vuln_soft>
      <prod name="simpleserver_www" vendor="analogx">
        <vers num="1.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0387" seq="2001-0387" published="2001-07-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0236.html" adv="1" patch="1">20010415 **SECURITY ADVISORY** - HylaFAX format string vulnerability</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0606.html">FreeBSD-SA-01:34</ref>
      <ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2001-Apr/0005.html" adv="1" patch="1">SuSE-SA:2001:15</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-041.php3" adv="1" patch="1">MDKSA-2001:041</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/175963" adv="1">20010412 HylaFAX vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2574" adv="1" patch="1">2574</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6377">hylafax-hfaxd-format-string(6377)</ref>
    </refs>
    <vuln_soft>
      <prod name="hylafax" vendor="hylafax">
        <vers num="4.0_pl0"/>
        <vers num="4.0_pl1"/>
        <vers num="4.0_pl2"/>
        <vers num="4.1_beta1"/>
        <vers num="4.1_beta2"/>
        <vers num="4.1_beta3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0388" seq="2001-0388" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">time server daemon timed allows remote attackers to cause a denial of service via malformed packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:28.timed.asc" adv="1" patch="1">FreeBSD-SA-01:28</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-034.php3" adv="1" patch="1">MDKSA-2001:034</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_007_nkitserv.html">SuSE-SA:2001:07</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6228">timed-remote-dos(6228)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.1" prev="1"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0389" seq="2001-0389" published="2001-07-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176100">20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2587" adv="1">2587</ref>
    </refs>
    <vuln_soft>
      <prod name="net.commerce" vendor="ibm">
        <vers num="3.1.2"/>
      </prod>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="5.1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0390" seq="2001-0390" published="2001-07-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176100">20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2588" adv="1">2588</ref>
    </refs>
    <vuln_soft>
      <prod name="net.commerce" vendor="ibm">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
      </prod>
      <prod name="net.commerce_hosting_server" vendor="ibm">
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
      </prod>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="5.1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0391" seq="2001-0391" published="2001-07-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0277.html">20010417 Advisory for Xitami 2.4d7, 2.5d4</ref>
    </refs>
    <vuln_soft>
      <prod name="xitami" vendor="imatix">
        <vers num="2.4d7" edition=":windows"/>
        <vers num="2.5d4" edition=":windows"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0392" seq="2001-0392" published="2001-06-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98633100728473&amp;w=2">20010403 def-2001-17: Navision Financials Server DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2539" adv="1" patch="1">2539</ref>
    </refs>
    <vuln_soft>
      <prod name="financials_server" vendor="navision">
        <vers num="2.50"/>
        <vers num="2.60" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0393" seq="2001-0393" published="2001-06-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98637870623514&amp;w=2">20010404 Re: def-2001-17: Navision Financials Server DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="financials_server" vendor="navision">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0394" seq="2001-0394" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0425.html" adv="1" patch="1">20010328 def-2001-15: Website Pro Remote Manager DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6295">website-pro-remote-dos(6295)</ref>
    </refs>
    <vuln_soft>
      <prod name="website_pro" vendor="oreilly">
        <vers num="3.0.37"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0395" seq="2001-0395" published="2001-07-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html" adv="1">20010410 Console 3200 telnetd problem.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2578" adv="1" patch="1">2578</ref>
    </refs>
    <vuln_soft>
      <prod name="consoleserver" vendor="lightwave">
        <vers num="3200"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0396" seq="2001-0396" published="2001-07-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html" adv="1">20010410 Console 3200 telnetd problem.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2578" adv="1" patch="1">2578</ref>
    </refs>
    <vuln_soft>
      <prod name="consoleserver" vendor="lightwave">
        <vers num="3200"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0397" seq="2001-0397" published="2001-06-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0454.html" adv="1">20010329 Silent Runner Collector - HELO buffer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="silent_runner_collector_src" vendor="silent_runner">
        <vers num="1.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0398" seq="2001-0398" published="2001-06-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT!  to misrepresent the attachment's type with a different icon.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0013.html" adv="1">20010402 ~..~!guano</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2530" adv="1" patch="1">2530</ref>
    </refs>
    <vuln_soft>
      <prod name="the_bat" vendor="ritlabs">
        <vers num="1.0_build1336"/>
        <vers num="1.0_build1349"/>
        <vers num="1.1"/>
        <vers num="1.011"/>
        <vers num="1.14"/>
        <vers num="1.015"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.028"/>
        <vers num="1.029"/>
        <vers num="1.031"/>
        <vers num="1.032"/>
        <vers num="1.33"/>
        <vers num="1.34"/>
        <vers num="1.035"/>
        <vers num="1.036"/>
        <vers num="1.037"/>
        <vers num="1.039"/>
        <vers num="1.041"/>
        <vers num="1.42"/>
        <vers num="1.42f"/>
        <vers num="1.043"/>
        <vers num="1.44"/>
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
        <vers num="1.48"/>
        <vers num="1.49"/>
        <vers num="1.101"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0399" seq="2001-0399" published="2001-06-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98633597813833&amp;w=2">20010403 CHINANSL Security Advisory(CSA-200111)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2533" adv="1" patch="1">2533</ref>
    </refs>
    <vuln_soft>
      <prod name="resin" vendor="caucho_technology">
        <vers num="1.2"/>
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0400" seq="2001-0400" published="2001-07-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/175506" adv="1">20010410 CGI - nph-maillist.pl vulnerability...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2563" adv="1" patch="1">2563</ref>
    </refs>
    <vuln_soft>
      <prod name="nph-maillist" vendor="matt_tourtillott">
        <vers num="3.0"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0401" seq="2001-0401" published="2001-06-18" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0394.html" adv="1" patch="1">20010327 Solaris /usr/bin/tip Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2475">2475</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6284">solaris-tip-bo(6284)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0402" seq="2001-0402" published="2001-06-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0338.html" adv="1" patch="1">FreeBSD-SA-01:32</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98679734015538&amp;w=2">20010408 A fragmentation attack against IP Filter</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6331">ipfilter-access-ports(6331)</ref>
    </refs>
    <vuln_soft>
      <prod name="ipfilter" vendor="darren_reed">
        <vers num="3.4.16" prev="1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.1" prev="1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0403" seq="2001-0403" published="2001-06-18" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0326.html" adv="1" patch="1">20010323 [ Hackerslab bug_paper ] SunOS application perfmon vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6267">solaris-perfmon-create-files(6267)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0404" seq="2001-0404" published="2001-06-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98583089425166&amp;w=2">20010328 CHINANSL Security Advisory(CSA-200106)</ref>
    </refs>
    <vuln_soft>
      <prod name="javaserver_web_dev_kit" vendor="sun">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0405" seq="2001-0405" published="2001-07-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0271.html" adv="1" patch="1">20010416 Tempest Security Techonologies -- Adivsory #01/2001 -- Linux IPTables</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-071.php3">MDKSA-2001:071</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-052.html" adv="1">RHSA-2001:052</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-084.html">RHSA-2001:084</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2602" adv="1" patch="1">2602</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6390">linux-netfilter-iptables(6390)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0406" seq="2001-0406" published="2001-07-02" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0305.html" adv="1" patch="1">20010417 Samba 2.0.8 security fix</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0319.html" adv="1" patch="1">20010418 TSLSA-#2001-0005 - samba</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0326.html" adv="1" patch="1">20010418 PROGENY-SA-2001-05: Samba /tmp vulnerabilities</ref>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0608.html">FreeBSD-SA-01:36</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000395">CLA-2001:395</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-015.0.txt" adv="1" patch="1">CSSA-2001-015.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-048" adv="1" patch="1">DSA-048</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/670568">VU#670568</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-040.php3">MDKSA-2001:040</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2617">2617</ref>
    </refs>
    <vuln_soft>
      <prod name="samba" vendor="samba">
        <vers num="2.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0407" seq="2001-0407" published="2001-06-27" modified="2019-10-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0237.html" adv="1">20010318 potential vulnerability of mysqld running with root privileges (can be used as good DoS or r00t expoloit)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0396.html" adv="1" patch="1">20010327 MySQL 3.23.36 is relased (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2522">2522</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6617">mysql-dot-directory-traversal(6617)</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23.36" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0408" seq="2001-0408" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98593106111968&amp;w=2">20010329 Immunix OS Security update for vim</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt" adv="1" patch="1">CSSA-2001-014.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-035.php3">MDKSA-2001:035</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_012_vim.html">SuSE-SA:2001:12</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-008.html" adv="1" patch="1">RHSA-2001:008</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2510" adv="1" patch="1">2510</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6259">vim-elevate-privileges(6259)</ref>
    </refs>
    <vuln_soft>
      <prod name="vim" vendor="vim_development_group">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0409" seq="2001-0409" published="2001-06-18" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt" adv="1" patch="1">CSSA-2001-014.0</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_012_vim.html">SuSE-SA:2001:12</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6628">vim-tmp-symlink(6628)</ref>
    </refs>
    <vuln_soft>
      <prod name="vim" vendor="vim_development_group">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0410" seq="2001-0410" published="2001-06-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98593642520755&amp;w=2">20010330 Virus Buster 2001(ver8.02) Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="virus_buster_2001" vendor="trend_micro">
        <vers num="8.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0411" seq="2001-0411" published="2001-06-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98658209505849&amp;w=2">20010406 Reliant Unix 5.43 / 5.44 ICMP port unreachable problem</ref>
    </refs>
    <vuln_soft>
      <prod name="reliant_unix" vendor="siemens">
        <vers num="5.44"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0412" seq="2001-0412" published="2001-06-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/arrowpoint-useraccnt-debug-pub.shtml" adv="1" patch="1">20010404 Cisco Content Services Switch User Account Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2559">2559</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6322">cisco-css-elevate-privileges(6322)</ref>
    </refs>
    <vuln_soft>
      <prod name="content_services_switch_11050" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="content_services_switch_11150" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="content_services_switch_11800" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0413" seq="2001-0413" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">BinTec X4000 Access router, and possibly other versions, allows remote attackers to cause a denial of service via a SYN port scan, which causes the router to hang.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0145.html" adv="1" patch="1">20010410 BinTec Router DoS: Workaround and Details</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98644414226344&amp;w=2">20010404 BinTec X4000 Access Router DoS Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98659862317070&amp;w=2">20010406 X4000 DoS: Details and workaround</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98697054804197&amp;w=2">20010409 BINTEC X1200</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6323">bintec-x4000-nmap-dos(6323)</ref>
    </refs>
    <vuln_soft>
      <prod name="x1000" vendor="bintec">
        <vers num=""/>
      </prod>
      <prod name="x1200" vendor="bintec">
        <vers num=""/>
      </prod>
      <prod name="x4000" vendor="bintec">
        <vers num="5.1.6_patch_10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0414" seq="2001-0414" published="2001-06-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:31.ntpd.asc">FreeBSD-SA-01:31</ref>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2001-004.txt.asc">NetBSD-SA2001-004</ref>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/sse073.ltr">SSE073</ref>
      <ref source="SCO" url="ftp://ftp.sco.com/SSE/sse074.ltr">SSE074</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0127.html">20010409 [ESA-20010409-01] xntp buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0225.html">20010413 PROGENY-SA-2001-02A: [UPDATE] ntpd remote buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0314.html">20010418 IBM MSS Outside Advisory Redistribution: IBM AIX: Buffer Overflow Vulnerability in (x)ntp</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000392">CLA-2001:392</ref>
      <ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2001-Apr/0000.html">SuSE-SA:2001:10</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98642418618512&amp;w=2">20010404 ntpd =&lt; 4.0.99k remote buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98654963328381&amp;w=2">20010405 Re: ntpd =&lt; 4.0.99k remote buffer overflow]</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98659782815613&amp;w=2">20010406 Immunix OS Security update for ntp and xntp3</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98679815917014&amp;w=2">20010408 [slackware-security] buffer overflow fix for NTP</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98683952401753&amp;w=2">20010409 ntp-4.99k23.tar.gz is available</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684202610470&amp;w=2">20010409 PROGENY-SA-2001-02: ntpd remote buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684532921941&amp;w=2">20010409 ntpd - new Debian 2.2 (potato) version is also vulnerable</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-013.0.txt">CSSA-2001-013</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-036.php3" adv="1" patch="1">MDKSA-2001:036</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-045.html">RHSA-2001:045</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2540" adv="1" patch="1">2540</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6321">ntpd-remote-bo(6321)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3831">oval:org.mitre.oval:def:3831</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-045">DSA-045</ref>
    </refs>
    <vuln_soft>
      <prod name="ntpd" vendor="dave_mills">
        <vers num="4.0.99"/>
        <vers num="4.0.99a"/>
        <vers num="4.0.99b"/>
        <vers num="4.0.99c"/>
        <vers num="4.0.99d"/>
        <vers num="4.0.99e"/>
        <vers num="4.0.99f"/>
        <vers num="4.0.99g"/>
        <vers num="4.0.99h"/>
        <vers num="4.0.99i"/>
        <vers num="4.0.99j"/>
        <vers num="4.0.99k" prev="1"/>
      </prod>
      <prod name="xntp3" vendor="dave_mills">
        <vers num="5.93"/>
        <vers num="5.93a"/>
        <vers num="5.93b"/>
        <vers num="5.93c"/>
        <vers num="5.93d"/>
        <vers num="5.93e"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0415" seq="2001-0415" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0275.html" adv="1" patch="1">20010320 Password stored in clear text vulnerability in real time stock trading program</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2495" adv="1" patch="1">2495</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6276">rediplus-weak-security(6276)</ref>
    </refs>
    <vuln_soft>
      <prod name="rediplus" vendor="redi">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0416" seq="2001-0416" published="2001-06-27" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000390" adv="1" patch="1">CLA-2001:390</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98477491130367&amp;w=2">20010316 Immunix OS Security update for sgml-tools</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-038" adv="1">DSA-038</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-030.php3" adv="1" patch="1">MDKSA-2001:030</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_016_sgmltool_txt.html">SuSE-SA:2001:16</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-027.html" adv="1" patch="1">RHSA-2001:027</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2506">2506</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2683">2683</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6201">sgmltools-symlink(6201)</ref>
    </refs>
    <vuln_soft>
      <prod name="sgml-tools" vendor="debian">
        <vers num="1.0.9.15"/>
      </prod>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0417" seq="2001-0417" published="2001-06-27" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0078.html" adv="1" patch="1">20010307 Security advisory: Unsafe temporary file handling in krb4</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-025.html">RHSA-2001:025</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="4"/>
        <vers num="5-1.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0418" seq="2001-0418" published="2001-07-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0223.html" adv="1">20010413 Exploitable NCM.at - Content Management System</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2584" adv="1" patch="1">2584</ref>
    </refs>
    <vuln_soft>
      <prod name="ncm_content_management_system" vendor="ncm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0419" seq="2001-0419" published="2001-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98692227816141&amp;w=2">20010410 Oracle Application Server shared library buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2569" adv="1">2569</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="4.0.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0420" seq="2001-0420" published="2001-06-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0128.html" adv="1" patch="1">20010409 talkback.cgi vulnerability may allow users to read any file</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2547" adv="1" patch="1">2547</ref>
    </refs>
    <vuln_soft>
      <prod name="talkback" vendor="way_to_the_web">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0421" seq="2001-0421" published="2001-07-02" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/177200">20010417 Re: SUN SOLARIS 5.6/5.7 FTP Globbing Exploit !</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2601" adv="1">2601</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0422" seq="2001-0422" published="2001-07-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0158.html" adv="1" patch="1">20010410 Solaris Xsun buffer overflow vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2561" adv="1" patch="1">2561</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6343">solaris-xsun-home-bo(6343)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A555">oval:org.mitre.oval:def:555</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0423" seq="2001-0423" published="2001-07-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0217.html" adv="1" patch="1">20010412 Solaris ipcs vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2581" adv="1" patch="1">2581</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6369">solaris-ipcs-bo(6369)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0424" seq="2001-0424" published="2001-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98744422105430&amp;w=2">20010415 BubbleMon 1.31</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2609" adv="1" patch="1">2609</ref>
    </refs>
    <vuln_soft>
      <prod name="bubblemon" vendor="timecop">
        <vers num="1.0"/>
        <vers num="1.0pl1"/>
        <vers num="1.0pl2"/>
        <vers num="1.0pl3"/>
        <vers num="1.0pl4"/>
        <vers num="1.0pl6"/>
        <vers num="1.0pl7"/>
        <vers num="1.0pl8"/>
        <vers num="1.0pl9"/>
        <vers num="1.1"/>
        <vers num="1.1test1"/>
        <vers num="1.1test2"/>
        <vers num="1.1test3"/>
        <vers num="1.1test4"/>
        <vers num="1.1test5"/>
        <vers num="1.1test6"/>
        <vers num="1.1test7"/>
        <vers num="1.2"/>
        <vers num="1.2test1"/>
        <vers num="1.3"/>
        <vers num="1.21"/>
        <vers num="1.21test1"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.31"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="6.2" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0425" seq="2001-0425" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/163942" adv="1" patch="1">20010219 Adcycle 0.78b Authentication</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2393" adv="1">2393</ref>
    </refs>
    <vuln_soft>
      <prod name="adcycle" vendor="adcycle">
        <vers num="0.77"/>
        <vers num="0.78b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0426" seq="2001-0426" published="2001-07-02" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0203.html" adv="1">20010411 [LSD] Solaris kcsSUNWIOsolf.so and dtsession vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0427" seq="2001-0427" published="2001-06-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.1" CVSS_base_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtml" adv="1" patch="1">20010328 VPN3000 Concentrator TELNET Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6298">cisco-vpn-telnet-dos(6298)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpn_3000_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3005_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3015_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3030_concentator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3060_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="vpn_3080_concentrator" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0428" seq="2001-0428" published="2001-07-02" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/vpn3k-ipoptions-vuln-pub.shtml" adv="1" patch="1">20010412 VPN 3000 Concentrator IP Options Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2573" adv="1" patch="1">2573</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6360">cisco-vpn-ip-dos(6360)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpn_3000_concentrator_series_software" vendor="cisco">
        <vers num="2.5.2.a"/>
        <vers num="2.5.2.b"/>
        <vers num="2.5.2.c"/>
        <vers num="2.5.2.d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0429" seq="2001-0429" published="2001-07-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-072.shtml">L-072</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cat5k-8021x-vuln-pub.shtml" adv="1" patch="1">20010416 Catalyst 5000 Series 802.1x Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2604" adv="1" patch="1">2604</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6379">cisco-catalyst-8021x-dos(6379)</ref>
    </refs>
    <vuln_soft>
      <prod name="catos" vendor="cisco">
        <vers num="4.5(11)"/>
        <vers num="4.5.10"/>
        <vers num="5.5(4b)"/>
        <vers num="5.5(6)"/>
        <vers num="6.1(1c)"/>
        <vers num="6.1(2)"/>
        <vers num="6.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0430" seq="2001-0430" published="2001-07-02" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6388">exuberant-ctags-symlink(6388)</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-046">DSA-046</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
        <vers num="3.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0431" seq="2001-0431" published="2001-07-02" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in iPlanet Web Server Enterprise Edition 4.x.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html">http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="iplanet">
        <vers num="4.x_enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0432" seq="2001-0432" published="2001-07-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0218.html" adv="1">20010413 Trend Micro Interscan VirusWall 3.01 vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2579" adv="1" patch="1">2579</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0433" seq="2001-0433" published="2001-06-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98655083231635&amp;w=2">20010405 Savant 3.0 Denial Of Service</ref>
    </refs>
    <vuln_soft>
      <prod name="savant_webserver" vendor="micheal_lamont">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0434" seq="2001-0434" published="2001-07-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="COMPAQ" url="http://ftp.support.compaq.com/patches/.new/html/SSRT0716-01.shtml" adv="1" patch="1">SSRT0716</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6355">compaq-activex-dos(6355)</ref>
    </refs>
    <vuln_soft>
      <prod name="presario" vendor="compaq">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0435" seq="2001-0435" published="2001-07-02" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98691775527457&amp;w=2">20010410 [wsir-01/02-03] PGP 7.0 Split Key/Cached Passphrase Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="pgp" vendor="pgp">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0436" seq="2001-0436" published="2001-07-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html" adv="1" patch="1">20010416 qDefense Advisory: DCForum allows remote read/write/execute</ref>
      <ref source="CONFIRM" url="http://www.dcscripts.com/FAQ/sec_2001_03_31.html" patch="1">http://www.dcscripts.com/FAQ/sec_2001_03_31.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2611" adv="1" patch="1">2611</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6392">dcforum-az-expr(6392)</ref>
    </refs>
    <vuln_soft>
      <prod name="dcforum" vendor="dcscripts">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
      <prod name="dcforum_2000" vendor="dcscripts">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0437" seq="2001-0437" published="2001-07-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html" adv="1" patch="1">20010416 qDefense Advisory: DCForum allows remote read/write/execute</ref>
      <ref source="CONFIRM" url="http://www.dcscripts.com/FAQ/sec_2001_03_31.html" adv="1" patch="1">http://www.dcscripts.com/FAQ/sec_2001_03_31.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2611" adv="1" patch="1">2611</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6393">dcforum-az-file-upload(6393)</ref>
    </refs>
    <vuln_soft>
      <prod name="dcforum" vendor="dcscripts">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
      <prod name="dcforum_2000" vendor="dcscripts">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0438" seq="2001-0438" published="2001-07-02" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0337.html" adv="1">20010418 Hole in Netopia's Mac OS X Timbuktu</ref>
    </refs>
    <vuln_soft>
      <prod name="timbuktu_mac" vendor="netopia">
        <vers num="initial"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0439" seq="2001-0439" published="2001-07-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html" adv="1" patch="1">FreeBSD-SA-01:35</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000389" patch="1">CLA-2001:389</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3" adv="1" patch="1">MDKSA-2001:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-022.html">RHSA-2001:022</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-023.html">RHSA-2001:023</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6261">licq-url-execute-commands(6261)</ref>
    </refs>
    <vuln_soft>
      <prod name="licq" vendor="licq">
        <vers num="1.0.2" prev="1"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5.1"/>
        <vers num="4.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0440" seq="2001-0440" published="2001-07-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html" adv="1" patch="1">FreeBSD-SA-01:35</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000389" adv="1" patch="1">CLA-2001:389</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3" adv="1" patch="1">MDKSA-2001:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-022.html">RHSA-2001:022</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-023.html">RHSA-2001:023</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6645">licq-logging-bo(6645)</ref>
    </refs>
    <vuln_soft>
      <prod name="licq" vendor="licq">
        <vers num="1.0.2" prev="1"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="4.0"/>
        <vers num="4.0es"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="ecommerce"/>
        <vers num="prg_graficos"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0441" seq="2001-0441" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0610.html" adv="1" patch="1">FreeBSD-SA-01:37</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000383">CLA-2001:383</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98471253131191&amp;w=2">20010316 Immunix OS Security update for slrn</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-040" adv="1" patch="1">DSA-040</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-028.php3" adv="1" patch="1">MDKSA-2001:028</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-028.html" adv="1" patch="1">RHSA-2001:028</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2493">2493</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6213">slrn-wrapping-bo(6213)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2" prev="1"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0442" seq="2001-0442" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0378.html" adv="1">20010421 Mercury for NetWare POP3 server vulnerable to remote buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/179217">20010424 Re: Mercury for NetWare POP3 server vulnerable to remote buffer overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6444.php">mercury-mta-bo(6444)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2641" adv="1" patch="1">2641</ref>
    </refs>
    <vuln_soft>
      <prod name="mercury_nlm" vendor="david_harris">
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="1.47"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0443" seq="2001-0443" published="2001-07-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0227.html" adv="1">20010413 QPC POPd Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="qvt_net" vendor="qpc_software">
        <vers num="5.0"/>
      </prod>
      <prod name="qvt_term_plus" vendor="qpc_software">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0444" seq="2001-0444" published="2001-07-02" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0380.html" adv="1">20010420 Bug in Cisco CBOS v2.3.0.053</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2635" adv="1">2635</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6453">cisco-cbos-gain-information(6453)</ref>
    </refs>
    <vuln_soft>
      <prod name="cbos" vendor="cisco">
        <vers num="2.3.053"/>
        <vers num="2.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0446" seq="2001-0446" published="2001-06-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98583082225053&amp;w=2">20010328 CHINANSL Security Advisory(CSA-200107)</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_commerce_suite" vendor="ibm">
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0447" seq="2001-0447" published="2001-06-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/171418" adv="1">20010326 602Pro Lansuite Denial Of Service 1.0.34</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2514" adv="1">2514</ref>
    </refs>
    <vuln_soft>
      <prod name="602pro_lan_suite" vendor="software602">
        <vers num="2000a_2000.0.1.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0448" seq="2001-0448" published="2001-06-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/171418" adv="1">20010326 602Pro Lansuite Denial Of Service 1.0.34</ref>
    </refs>
    <vuln_soft>
      <prod name="602pro_lan_suite" vendor="software602">
        <vers num="2000a_1.0.34" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0449" seq="2001-0449" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/166211" adv="1">20010302 def-2001-09: Winzip32 zipandemail Buffer Overflow</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6191">winzip-zipandemail-bo(6191)</ref>
    </refs>
    <vuln_soft>
      <prod name="winzip" vendor="winzip">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0450" seq="2001-0450" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0533.html" adv="1">20010303 Broker Ftp Server 5.0 Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&amp;P=0&amp;C=0" adv="1">http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&amp;P=0&amp;C=0</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6189">broker-ftp-list-directories(6189)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6190">broker-ftp-delete-files(6190)</ref>
    </refs>
    <vuln_soft>
      <prod name="broker_ftp_server" vendor="transsoft">
        <vers num="5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0451" seq="2001-0451" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6202">indexu-gain-access(6202)</ref>
    </refs>
    <vuln_soft>
      <prod name="indexu" vendor="sentraweb">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="2.0beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0452" seq="2001-0452" published="2001-06-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html">http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/180506" adv="1" patch="1">20010428 Vulnerabilities in BRS WebWeaver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2676" adv="1">2676</ref>
    </refs>
    <vuln_soft>
      <prod name="webweaver" vendor="brs">
        <vers num="0.49_beta"/>
        <vers num="0.50_beta"/>
        <vers num="0.51_beta"/>
        <vers num="0.52_beta"/>
        <vers num="0.60_beta"/>
        <vers num="0.61_beta"/>
        <vers num="0.62_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0453" seq="2001-0453" published="2001-06-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0519.html" adv="1" patch="1">20010428 Vulnerabilities in BRS WebWeaver</ref>
      <ref source="CONFIRM" url="http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html">http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2675">2675</ref>
    </refs>
    <vuln_soft>
      <prod name="webweaver" vendor="brs">
        <vers num="0.49_beta"/>
        <vers num="0.50_beta"/>
        <vers num="0.51_beta"/>
        <vers num="0.52_beta"/>
        <vers num="0.60_beta"/>
        <vers num="0.61_beta"/>
        <vers num="0.62_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0454" seq="2001-0454" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0532.html" adv="1" patch="1">20010303 SlimServe HTTPd ver. 1.1a Directory Traversal</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6186">slimserve-httpd-directory-traversal(6186)</ref>
    </refs>
    <vuln_soft>
      <prod name="slimserve" vendor="whitsoft">
        <vers num="1.1a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0455" seq="2001-0455" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/Aironet340-pub.shtml" adv="1" patch="1">20010307 Access to the Cisco Aironet 340 Series Wireless Bridge via Web Interface</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6200">cisco-aironet-web-access(6200)</ref>
    </refs>
    <vuln_soft>
      <prod name="aironet_340" vendor="cisco">
        <vers num="8.55" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0456" seq="2001-0456" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-032" adv="1" patch="1">DSA-032</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6208">proftpd-postinst-root(6208)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0457" seq="2001-0457" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-035" adv="1" patch="1">DSA-035</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6211">man2html-remote-dos(6211)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0458" seq="2001-0458" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-034" adv="1" patch="1">DSA-034</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-027.php3" adv="1" patch="1">MDKSA-2001:027</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_008_eperl.html">SuSE-SA:2001:08</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2464" adv="1" patch="1">2464</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6198">linux-eperl-bo(6198)</ref>
    </refs>
    <vuln_soft>
      <prod name="eperl" vendor="ralf_s._engelschall">
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0459" seq="2001-0459" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98408897106411&amp;w=2">20010308 ascdc Buffer Overflow Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6204">ascdc-afterstep-bo(6204)</ref>
    </refs>
    <vuln_soft>
      <prod name="afterstep" vendor="afterstep.org">
        <vers num=""/>
      </prod>
      <prod name="ascdc" vendor="rob_malda">
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0460" seq="2001-0460" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/167406" adv="1" patch="1">20010308 def-2001-10: Websweeper Infinite HTTP Request DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6214">websweeper-http-dos(6214)</ref>
    </refs>
    <vuln_soft>
      <prod name="websweeper" vendor="baltimore_technologies">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0461" seq="2001-0461" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0109.html" adv="1" patch="1">20010309 Cgisecurity.com advisory #4 The Free On-line Dictionary of Computing</ref>
      <ref source="CONFIRM" url="http://wombat.doc.ic.ac.uk/foldoc/index.html">http://wombat.doc.ic.ac.uk/foldoc/index.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6217">foldoc-cgi-execute-commands(6217)</ref>
    </refs>
    <vuln_soft>
      <prod name="foldoc" vendor="denis_howe">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0462" seq="2001-0462" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0426.html" adv="1">20010424 Advisory for perl webserver</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2648" adv="1">2648</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6451">perl-webserver-directory-traversal(6451)</ref>
    </refs>
    <vuln_soft>
      <prod name="perl_web_server" vendor="spencer_christensen">
        <vers num="0.0.1"/>
        <vers num="0.0.2"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.9"/>
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0463" seq="2001-0463" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0506.html" adv="1" patch="1">20010427 PerlCal (CGI) show files vulnerability</ref>
      <ref source="CONFIRM" url="http://www.perlcal.com/calendar/docs/bugs.txt">http://www.perlcal.com/calendar/docs/bugs.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2663" adv="1" patch="1">2663</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6480">perlcal-calmake-directory-traversal(6480)</ref>
    </refs>
    <vuln_soft>
      <prod name="perlcal" vendor="acme_labs">
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.9"/>
        <vers num="2.9a"/>
        <vers num="2.9b"/>
        <vers num="2.9c"/>
        <vers num="2.9d"/>
        <vers num="2.9e"/>
        <vers num="2.13"/>
        <vers num="2.18"/>
        <vers num="2.80"/>
        <vers num="2.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0464" seq="2001-0464" published="2001-07-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98761402029302&amp;w=2">20010417 Cyberscheduler remote root compromise</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2628" adv="1" patch="1">2628</ref>
    </refs>
    <vuln_soft>
      <prod name="cyberscheduler" vendor="crosswind">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0465" seq="2001-0465" published="2001-06-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653594732053&amp;w=2">20010405</ref>
      <ref source="CONFIRM" url="http://www.turbotax.com/atr/update/">http://www.turbotax.com/atr/update/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6622">turbotax-save-passwords(6622)</ref>
    </refs>
    <vuln_soft>
      <prod name="turbo_tax" vendor="intuit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0466" seq="2001-0466" published="2001-06-18" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98633176230748&amp;w=2">20010403 new advisory</ref>
    </refs>
    <vuln_soft>
      <prod name="ustorekeeper_online_shopping_system" vendor="microburst">
        <vers num="1.61"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0467" seq="2001-0467" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.robtex.com/files/viking/beta/chglog.txt">http://www.robtex.com/files/viking/beta/chglog.txt</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/178935" adv="1" patch="1">20010423 Vulnerability in Viking Web Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2643" adv="1" patch="1">2643</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6450">viking-dot-directory-traversal(6450)</ref>
    </refs>
    <vuln_soft>
      <prod name="viking_server" vendor="robtex">
        <vers num="1.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0468" seq="2001-0468" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0163.html" adv="1">20010313 Buffer oveflow in FTPFS (linux kernel module)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6234">ftpfs-bo(6234)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftpfs" vendor="ftpfs">
        <vers num="0.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0469" seq="2001-0469" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-03/0163.html" adv="1" patch="1">FreeBSD-SA-01:29</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2473" adv="1" patch="1">2473</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6229">rwhod-remote-dos(6229)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0470" seq="2001-0470" published="2001-06-27" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0160.html" adv="1">20010313 Solaris 5.8 snmpd Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0181.html" adv="1">20010315 Re: Solaris 5.8 snmpd Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6239">snmpd-argv-bo(6239)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0471" seq="2001-0471" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/160648" adv="1" patch="1">20010205 SSHD-1 Logging Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2345" adv="1" patch="1">2345</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.30" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0472" seq="2001-0472" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0243.html" adv="1" patch="1">20010320 def-2001-12: Hursley Software Laboratories Consumer Transaction Framework DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6250">hslctf-http-dos(6250)</ref>
    </refs>
    <vuln_soft>
      <prod name="high_availability_cluster_multiprocessing" vendor="ibm">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0473" seq="2001-0473" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0246.html" adv="1" patch="1">20010320 Trustix Security Advisory - mutt</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000385">CLA-2001:385</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98473109630421&amp;w=2">20010315 Immunix OS Security update for mutt</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-031.php3" adv="1" patch="1">MDKSA-2001-031</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-029.html" adv="1" patch="1">RHSA-2001:029</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6235">mutt-imap-format-string(6235)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mutt" vendor="mutt">
        <vers num="1.2.5" prev="1"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num=""/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0474" seq="2001-0474" published="2001-06-27" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-029.php3" adv="1" patch="1">MDKSA-2001:029</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6231">mesa-utahglx-symlink(6231)</ref>
    </refs>
    <vuln_soft>
      <prod name="mesa" vendor="brian_paul">
        <vers num="3.3-14" prev="1"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0475" seq="2001-0475" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0180.html" adv="1" patch="1">20010315 vBulletin allows arbitrary code execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2474" adv="1">2474</ref>
      <ref source="CONFIRM" url="http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&amp;threadid=10839" adv="1" patch="1">http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&amp;threadid=10839</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6237">vbulletin-php-elevate-privileges(6237)</ref>
    </refs>
    <vuln_soft>
      <prod name="vbulletin" vendor="jelsoft">
        <vers num="1.1.5" prev="1"/>
        <vers num="2.0_beta_2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0476" seq="2001-0476" published="2001-06-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0233.html" adv="1">20010318 Aspseek Buffer Overflow</ref>
      <ref source="CONFIRM" url="http://www.aspseek.org/changes.html" patch="1">http://www.aspseek.org/changes.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2492" adv="1">2492</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6248">aspseek-scgi-bo(6248)</ref>
    </refs>
    <vuln_soft>
      <prod name="aspseek" vendor="swsoft">
        <vers num="1.0"/>
        <vers num="1.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0477" seq="2001-0477" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in WebCalendar 0.9.26 allows remote command execution.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0392.html" adv="1" patch="1">20010423 (SRPRE00004) WebCalendar 0.9.26</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2639" adv="1">2639</ref>
    </refs>
    <vuln_soft>
      <prod name="webcalendar" vendor="webcalendar">
        <vers num="0.9.8"/>
        <vers num="0.9.11"/>
        <vers num="0.9.15"/>
        <vers num="0.9.16"/>
        <vers num="0.9.19"/>
        <vers num="0.9.20"/>
        <vers num="0.9.21"/>
        <vers num="0.9.22"/>
        <vers num="0.9.23"/>
        <vers num="0.9.24"/>
        <vers num="0.9.25"/>
        <vers num="0.9.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0478" seq="2001-0478" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html" adv="1" patch="1">20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2642" adv="1" patch="1">2642</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="2.2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0479" seq="2001-0479" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html" adv="1" patch="1">20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1</ref>
      <ref source="CONFIRM" url="http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13">http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2640" adv="1" patch="1">2640</ref>
    </refs>
    <vuln_soft>
      <prod name="phppgadmin" vendor="phppgadmin">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0480" seq="2001-0480" published="2001-06-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0523.html" adv="1" patch="1">20010428 Vulnerabilities in Alex's FTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2668" adv="1">2668</ref>
    </refs>
    <vuln_soft>
      <prod name="alexs_ftp_server" vendor="alex_linde">
        <vers num="0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0481" seq="2001-0481" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-043.php3" adv="1" patch="1">MDKSA-2001:043</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6494">linux-rpmdrake-temp-file(6494)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0482" seq="2001-0482" published="2001-06-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys via calls to sysctl.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0475.html" adv="1" patch="1">20010330 Serious Pitbull LX Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6623">pitbull-lx-modify-kernel(6623)</ref>
    </refs>
    <vuln_soft>
      <prod name="pitbull_lx" vendor="argus_systems">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0483" seq="2001-0483" published="2001-06-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0359.html" adv="1" patch="1">20010324 Raptor 6.5 http vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/171953" adv="1" patch="1">20010327 RE: Raptor 6.5 http vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2517" adv="1" patch="1">2517</ref>
    </refs>
    <vuln_soft>
      <prod name="raptor_firewall" vendor="symantec">
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0484" seq="2001-0484" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0482.html" adv="1">20010425 Tektronix (Xerox) PhaserLink 850 Webserver Vulnerability (NEW)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6482">tektronix-phaserlink-webserver-backdoor(6482)</ref>
    </refs>
    <vuln_soft>
      <prod name="phaserlink" vendor="tek">
        <vers num="850"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0485" seq="2001-0485" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010701-01-P">20010701-01-P</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0475.html" adv="1">20010426 IRIX /usr/lib/print/netprint local root symbols exploit.</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0502.html">20010427 Re: IRIX /usr/lib/print/netprint local root symbols exploit.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2656" adv="1" patch="1">2656</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6473">irix-netprint-shared-library(6473)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0486" seq="2001-0486" published="2001-07-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0000.html" patch="1">20010501 Re: Proof of concept DoS against novell border manager enterprise edition 3.5</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0020.html" adv="1">20010402 (no subject)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98779821207867&amp;w=2">20010420 Novell BorderManager 3.5 VPN Denial of Service</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98865027328391&amp;w=2">20010429 Proof of concept DoS against novell border manager enterprise</ref>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2959062.htm" adv="1" patch="1">http://support.novell.com/cgi-bin/search/searchtid.cgi?/2959062.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2623" adv="1" patch="1">2623</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6429">bordermanager-vpn-syn-dos(6429)</ref>
    </refs>
    <vuln_soft>
      <prod name="bordermanager" vendor="novell">
        <vers num="3.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0487" seq="2001-0487" published="2001-06-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6996.php">aix-snmpd-rst-dos(6996)</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17630&amp;apar=only">IY17630</ref>
    </refs>
    <vuln_soft>
      <prod name="aix_snmp" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0488" seq="2001-0488" published="2001-06-27" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2646" adv="1" patch="1">2646</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0104-149">HPSBUX0104-149</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6447">hp-pcltotiff-insecure-permissions(6447)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0489" seq="2001-0489" published="2001-06-27" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://archives.neohapsis.com/archives/linux/redhat/2001-q2/0043.html" adv="1" patch="1">RHSA-2001:053</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0231.html">20010417 gftp exploitable?</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-057">DSA-057</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2657">2657</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6478">gftp-format-string(6478)</ref>
    </refs>
    <vuln_soft>
      <prod name="gftp" vendor="gftp">
        <vers num="2.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0490" seq="2001-0490" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0518.html" adv="1" patch="1">20010429 Winamp 2.6x / 2.7x buffer overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="winamp" vendor="nullsoft">
        <vers num="2.6x"/>
        <vers num="2.7x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0491" seq="2001-0491" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0465.html" adv="1" patch="1">20010425 Vulnerabilities in RaidenFTPD Server</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6455">raidenftpd-dot-directory-traversal(6455)</ref>
    </refs>
    <vuln_soft>
      <prod name="raidenftpd" vendor="team_johnlong">
        <vers num="2.1_build_947"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0492" seq="2001-0492" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0427.html" adv="1">20010424 Advisory for Netcruiser</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2650" adv="1">2650</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6468">netcruiser-server-path-disclosure(6468)</ref>
    </refs>
    <vuln_soft>
      <prod name="netcruiser_web_server" vendor="netcruiser_software">
        <vers num="0.1.2.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0493" seq="2001-0493" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0428.html" adv="1">20010424 Advisory for Small HTTP Server</ref>
      <ref source="CONFIRM" url="http://home.lanck.net/mf/srv/index.htm">http://home.lanck.net/mf/srv/index.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2649" adv="1">2649</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6446">small-http-aux-dos(6446)</ref>
    </refs>
    <vuln_soft>
      <prod name="small_http_server" vendor="max_feoktistov">
        <vers num="2.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0494" seq="2001-0494" published="2001-06-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0433.html" adv="1" patch="1">20010424 IPSwitch IMail 6.06 SMTP Remote System Access Vulnerability</ref>
      <ref source="CONFIRM" url="http://ipswitch.com/Support/IMail/news.html">http://ipswitch.com/Support/IMail/news.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6445">ipswitch-imail-smtp-bo(6445)</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.06" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0495" seq="2001-0495" published="2001-06-27" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0490.html" adv="1" patch="1">20010426 Vulnerability in WebXQ Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2660" adv="1" patch="1">2660</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6466">webxq-dot-directory-traversal(6466)</ref>
    </refs>
    <vuln_soft>
      <prod name="webxq" vendor="datawizard">
        <vers num="2.1.204"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0496" seq="2001-0496" published="2001-06-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-046.php3" adv="1" patch="1">MDKSA-2001:046</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-059.html" adv="1" patch="1">RHSA-2001:059</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6856">kdelibs-kdesu-insecure-tmpfile(6856)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="2007"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.1" edition=":i386"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0497" seq="2001-0497" published="2001-07-21" modified="2018-09-20" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise78.php" adv="1" patch="1">20010611 BIND Inadvertent Local Exposure of HMAC-MD5 (TSIG) Keys</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6694" adv="1">bind-local-key-exposure(6694)</ref>
    </refs>
    <vuln_soft>
      <prod name="bind" vendor="isc">
        <vers num="8.2.4" prev="1"/>
        <vers num="9.0"/>
        <vers num="9.0.0" edition="rc1"/>
        <vers num="9.0.0" edition="rc2"/>
        <vers num="9.0.0" edition="rc3"/>
        <vers num="9.0.0" edition="rc4"/>
        <vers num="9.0.0" edition="rc5"/>
        <vers num="9.0.0" edition="rc6"/>
        <vers num="9.0.1" edition="rc1"/>
        <vers num="9.0.1" edition="rc2"/>
        <vers num="9.1"/>
        <vers num="9.1.0" edition="rc1"/>
        <vers num="9.1.1" edition="rc1"/>
        <vers num="9.1.1" edition="rc2"/>
        <vers num="9.1.1" edition="rc3"/>
        <vers num="9.1.1" edition="rc4"/>
        <vers num="9.1.1" edition="rc5"/>
        <vers num="9.1.1" edition="rc6"/>
        <vers num="9.1.1" edition="rc7"/>
        <vers num="9.1.2" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0498" seq="2001-0498" published="2001-07-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/049.asp">20010627 Oracle 8i SQLNet Header Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0499" seq="2001-0499" published="2001-07-21" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-16.html">CA-2001-16</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/620495">VU#620495</ref>
      <ref source="NAI" url="http://www.nai.com/research/covert/advisories/050.asp">20010627 Vulnerability in Oracle 8i TNS Listener</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2941">2941</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6758">oracle-tns-listener-bo(6758)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0500" seq="2001-0500" published="2001-07-21" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-13.html" adv="1" patch="1">CA-2001-13</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-098.shtml">L-098</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6705.php">iis-isapi-idq-bo(6705)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/191873">20010618 All versions of Microsoft Internet Information Services, Remote buffer overflow (SYSTEM Level Access)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2880">2880</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-033">MS01-033</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A197">oval:org.mitre.oval:def:197</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
      <prod name="indexing_service" vendor="microsoft">
        <vers num="" edition=":windows_2000"/>
      </prod>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="6.0" prev="1" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0501" seq="2001-0501" published="2001-07-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99325144322224&amp;w=2">20010622 Fwd: Microsoft Word macro vulnerability advisory MS01-034</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2876" adv="1" patch="1">2876</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-034">MS01-034</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6732">msword-macro-bypass-security(6732)</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="97" edition="sr1"/>
        <vers num="97" edition="sr2"/>
        <vers num="98" edition=":mac"/>
        <vers num="2000" edition="sr1"/>
        <vers num="2000" edition="sr1a"/>
        <vers num="2000" edition="sr2"/>
        <vers num="2001" edition=":mac"/>
        <vers num="2002" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0502" seq="2001-0502" published="2001-07-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-101.shtml">L-101</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2929">2929</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-036">MS01-036</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6745">win2k-ldap-change-passwords(6745)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0503" seq="2001-0503" published="2001-07-21" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/5368.php">netmeeting-desktop-sharing-dos(5368)</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-077">MS00-077</ref>
    </refs>
    <vuln_soft>
      <prod name="netmeeting" vendor="microsoft">
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0504" seq="2001-0504" published="2001-08-14" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activities such as mail relaying.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-107.shtml">L-107</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/435963">VU#435963</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2988">2988</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-037">MS01-037</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6803">win2k-smtp-mail-relay(6803)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0505" seq="2001-0505" published="2001-10-30" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/581603">VU#581603</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/994851">VU#994851</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3089">3089</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-039">MS01-039</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6882">sfu-nfs-dos(6882)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6883">sfu-telnet-dos(6883)</ref>
    </refs>
    <vuln_soft>
      <prod name="services" vendor="microsoft">
        <vers num="2.0" edition=":unix"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0506" seq="2001-0506" published="2001-09-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99802093532233&amp;w=2">20010817 NSFOCUS SA2001-06 : Microsoft IIS ssinc.dll Buffer Overflow Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/242541">20011127 IIS Server Side Include Buffer overflow exploit code</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-132.shtml">L-132</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3190" adv="1" patch="1">3190</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044">MS01-044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6984">iis-ssi-directive-bo(6984)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0507" seq="2001-0507" published="2001-09-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/205069">20010816 ENTERCEPT SECURITY ALERT: Privilege Escalation Vulnerability in Microsoft IIS</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-132.shtml">L-132</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044">MS01-044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6985">iis-relative-path-privilege-elevation(6985)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A909">oval:org.mitre.oval:def:909</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A912">oval:org.mitre.oval:def:912</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0508" seq="2001-0508" published="2001-09-20" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/182579">20010506 IIS 5.0 PROPFIND DOS #2</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6982.php">iis-webdav-long-request-dos(6982)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2690">2690</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044">MS01-044</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0509" seq="2001-0509" published="2001-09-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-041">MS01-041</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A82">oval:org.mitre.oval:def:82</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="2000" prev="1"/>
      </prod>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000" prev="1"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0513" seq="2001-0513" published="2001-07-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oracle listener process on Windows NT redirects connection requests to another port and creates a separate thread to process the request, which allows remote attackers to cause a denial of service by repeatedly connecting to the Oracle listener but not connecting to the redirected port.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/105259">VU#105259</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise81.php" adv="1" patch="1">20010619 Oracle Redirect Denial of Service</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6717">oracle-listener-redirect-dos(6717)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle9i" vendor="oracle">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0514" seq="2001-0514" published="2001-07-21" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2896">2896</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise83.php" adv="1" patch="1">20010620 Multiple Vendor 802.11b Access Point SNMP authentication flaw</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6576">atmel-vnetb-ap-snmp-security(6576)</ref>
    </refs>
    <vuln_soft>
      <prod name="802.11b_vnet-b_access_point" vendor="atmel">
        <vers num="1.3" prev="1"/>
      </prod>
      <prod name="wap11" vendor="linksys">
        <vers num=""/>
      </prod>
      <prod name="me102" vendor="netgear">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0515" seq="2001-0515" published="2001-07-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf">http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise82.php" adv="1" patch="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="7.3"/>
      </prod>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.6"/>
        <vers num="8.1.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0516" seq="2001-0516" published="2001-07-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf">http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise82.php" adv="1" patch="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num=""/>
      </prod>
      <prod name="oracle9i" vendor="oracle">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0517" seq="2001-0517" published="2001-07-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf">http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise82.php" adv="1" patch="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6715">oracle-listener-data-transport-dos(6715)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle8i" vendor="oracle">
        <vers num="8.1.6"/>
        <vers num="8.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0518" seq="2001-0518" published="2001-07-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Oracle listener before Oracle 9i allows attackers to cause a denial of service by repeatedly sending the first portion of a fragmented Oracle command without sending the remainder of the command, which causes the listener to hang.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/alerts.htm">http://otn.oracle.com/deploy/security/alerts.htm</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise82.php" adv="1" patch="1">20010515 Multiple Oracle Listener Denial of Service Vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6716">oracle-listener-fragmentation-dos(6716)</ref>
    </refs>
    <vuln_soft>
      <prod name="oracle9i" vendor="oracle">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0519" seq="2001-0519" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0282.html" adv="1" patch="1">20010529 Aladdin eSafe Gateway Filter Bypass - Updated Advisory</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6580">esafe-gateway-bypass-filtering(6580)</ref>
    </refs>
    <vuln_soft>
      <prod name="esafe_gateway" vendor="aladdin_knowledge_systems">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0520" seq="2001-0520" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0284.html" adv="1">20010529 Aladdin eSafe Gateway Script-filtering Bypass through HTML tags</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6580">esafe-gateway-bypass-filtering(6580)</ref>
    </refs>
    <vuln_soft>
      <prod name="esafe_gateway" vendor="aladdin_knowledge_systems">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0521" seq="2001-0521" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0285.html" adv="1">20010529 Aladdin eSafe Gateway Script-filtering Bypass through Unicode Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6580">esafe-gateway-bypass-filtering(6580)</ref>
    </refs>
    <vuln_soft>
      <prod name="esafe_gateway" vendor="aladdin_knowledge_systems">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0522" seq="2001-0522" published="2001-08-14" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000399">CLA-2001:399</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01">IMNX-2001-70-023-01</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/188218">20010601 The GnuPG format string bug (was: TSLSA-2001-0009 - GnuPG)</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt">CSSA-2001-020.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-061">DSA-061</ref>
      <ref source="CONFIRM" url="http://www.gnupg.org/whatsnew.html#rn20010529">http://www.gnupg.org/whatsnew.html#rn20010529</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/403051">VU#403051</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3" adv="1" patch="1">MDKSA-2001:053</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html">SuSE-SA:2001:020</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-073.html">RHSA-2001:073</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2797">2797</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html">TLSA2001028</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6642">gnupg-tty-format-string(6642)</ref>
    </refs>
    <vuln_soft>
      <prod name="privacy_guard" vendor="gnu">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0523" seq="2001-0523" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html" adv="1">20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0197.html" adv="1">20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6563">eeye-secureiis-bypass-detection(6563)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6564">eeye-secureiis-directory-traversal(6564)</ref>
    </refs>
    <vuln_soft>
      <prod name="secureiis" vendor="eeye_digital_security">
        <vers num="1.0.2"/>
      </prod>
      <prod name="securells" vendor="eeye_digital_security">
        <vers num="1.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0524" seq="2001-0524" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html" adv="1">20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0197.html" adv="1">20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6574">eeye-secureiis-http-header-bo(6574)</ref>
    </refs>
    <vuln_soft>
      <prod name="securells" vendor="eeye_digital_security">
        <vers num="1.0.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0525" seq="2001-0525" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and earlier, and possibly other operating systems, allows local users to gain privileges via a long first command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0193.html" adv="1" patch="1">20010519 dqs 3.2.7 local root exploit.</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0195.html" adv="1" patch="1">20010519 Re: dqs 3.2.7 local root exploit.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2749">2749</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6577">dqs-dsh-bo(6577)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0526" seq="2001-0526" published="2001-08-14" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privileges via the OPENWINHOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0258.html" adv="1" patch="1">20010528 [synnergy] - Solaris mailtool(1) buffer overflow vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6626">solaris-mailtool-openwinhome-bo(6626)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition=":sparc"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0527" seq="2001-0527" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0122.html" adv="1">20010515 DCForum Password File Manipukation Vulnerability (qDefense Advisory Number QDAV-5-2000-2)</ref>
      <ref source="CONFIRM" url="http://www.dcscripts.com/dcforum/dcfNews/167.html" patch="1">http://www.dcscripts.com/dcforum/dcfNews/167.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2728">2728</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6538">dcforum-cgi-admin-access(6538)</ref>
    </refs>
    <vuln_soft>
      <prod name="dcforum" vendor="dcscripts">
        <vers num="6.0"/>
      </prod>
      <prod name="dcforum_2000" vendor="dcscripts">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0528" seq="2001-0528" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0044.html" adv="1">20010507 Oracle's ADI 7.1.1.10.1 Major security hole</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0223.html" adv="1" patch="1">20010522 Vulnerability in Oracle E-Business Suite Release 11i Applications Desktop Integrator</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2694" adv="1" patch="1">2694</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6501">oracle-adi-plaintext-passwords(6501)</ref>
    </refs>
    <vuln_soft>
      <prod name="e-business_suite" vendor="oracle">
        <vers num="11i"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0529" seq="2001-0529" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-010.txt.asc" adv="1" patch="1">NetBSD-SA2001-010</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0322.html" adv="1">20010604 SSH allows deletion of other users files...</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0007.html" adv="1">20010604 Re: SSH allows deletion of other users files...</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000431">CLA-2001:431</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01">IMNX-2001-70-034-01</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/188737">20010605 OpenSSH_2.5.2p2 RH7.0 &lt;- version info</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-023.0.txt" adv="1">CSSA-2001-023.0</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/655259">VU#655259</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata29.html">20010612</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2825" adv="1" patch="1">2825</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6676">openssh-symlink-file-deletion(6676)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="2.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0530" seq="2001-0530" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Spearhead NetGAP 200 and 300 before build 78 allow a remote attacker to bypass file blocking and content inspection via specially encoded URLs which include '%' characters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0256.html" adv="1">20010528 Vulnerability discovered in SpearHead NetGap</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0047.html" adv="1" patch="1">20010607 SpearHead Security NetGAP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2798" adv="1" patch="1">2798</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6625">netgap-unicode-bypass-filter(6625)</ref>
    </refs>
    <vuln_soft>
      <prod name="netgap_200" vendor="spearhead">
        <vers num="78" prev="1"/>
      </prod>
      <prod name="netgap_300" vendor="spearhead">
        <vers num="78" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0533" seq="2001-0533" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in libi18n library in IBM AIX 5.1 and 4.3.x allows local users to gain root privileges via a long LANG environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-123.shtml">L-123</ref>
      <ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/85256A3400529A8685256A8D00804A37/$file/oar271.txt" adv="1" patch="1">MSS-OAR-E01-2001:271.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6863">aix-libi18n-lang-bo(6863)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0534" seq="2001-0534" published="2001-07-21" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/898931">VU#898931</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2989">2989</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/alerts.php">20010705 Remote Buffer Overflow in Multiple RADIUS Implementations</ref>
    </refs>
    <vuln_soft>
      <prod name="radius" vendor="lucent">
        <vers num="2.1.2"/>
      </prod>
      <prod name="radius" vendor="merit">
        <vers num="3.6b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0535" seq="2001-0535" published="2001-10-30" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ALLAIRE" url="http://www.allaire.com/Handlers/index.cfm?ID=21700" adv="1">MPSB01-08</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise92.php" adv="1">20010807 Remote Vulnerabilities in Macromedia ColdFusion Example Applications</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="macromedia">
        <vers num="4.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0537" seq="2001-0537" published="2001-07-21" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="9.3" CVSS_base_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-14.html" adv="1" patch="1">CA-2001-14</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-106.shtml">L-106</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html" adv="1" patch="1">20010627 IOS HTTP authorization vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/1601227034.20010702112207@olympos.org">20010702 Cisco IOS HTTP Configuration Exploit</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/20010703011650.60515.qmail@web14910.mail.yahoo.com">20010702 ios-http-auth.sh</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/4.3.2.7.2.20010629095801.0c3e6a70@brussels.cisco.com">20010629 Re: Cisco Security Advisory: IOS HTTP authorization vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/Pine.LNX.3.96.1010702134611.22995B-100000@Lib-Vai.lib.asu.edu">20010702 Cisco device HTTP exploit...</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2936" adv="1" patch="1">2936</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6749">cisco-ios-admin-access(6749)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.3"/>
        <vers num="11.3aa"/>
        <vers num="11.3da"/>
        <vers num="11.3db"/>
        <vers num="11.3ha"/>
        <vers num="11.3ma"/>
        <vers num="11.3na"/>
        <vers num="11.3t"/>
        <vers num="11.3xa"/>
        <vers num="12.0"/>
        <vers num="12.0(5)xk"/>
        <vers num="12.0(7)xk"/>
        <vers num="12.0(10)w5(18g)"/>
        <vers num="12.0(14)w5(20)"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0st"/>
        <vers num="12.0t"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xn"/>
        <vers num="12.0xp"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xu"/>
        <vers num="12.0xv"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1cx"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ec"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1ez"/>
        <vers num="12.1t"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xk"/>
        <vers num="12.1xl"/>
        <vers num="12.1xm"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xs"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1ya"/>
        <vers num="12.1yb"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.1yf"/>
        <vers num="12.2"/>
        <vers num="12.2t"/>
        <vers num="12.2xa"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xh"/>
        <vers num="12.2xq"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0538" seq="2001-0538" published="2001-08-14" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99496431214078&amp;w=2">20010712 MS Office XP - the more money I give to Microsoft, the more vulnerable my Windows computers are</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-113.shtml">L-113</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/131569">VU#131569</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0107&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=862">20010712 Vulnerability in IE/Outlook ActiveX control</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3025">3025</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-038">MS01-038</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6831">outlook-activex-view-control(6831)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="2002" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0540" seq="2001-0540" published="2001-10-30" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3099">3099</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-040">MS01-040</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6912">win-terminal-rdp-dos(6912)</ref>
    </refs>
    <vuln_soft>
      <prod name="terminal_server" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0541" seq="2001-0541" published="2001-09-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/187001" adv="1">20010527 Microsoft Windows Media Player Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3105">3105</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-042">MS01-042</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6907">mediaplayer-nsc-bo(6907)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="6.4"/>
        <vers num="7"/>
        <vers num="7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0542" seq="2001-0542" published="2001-12-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100891252317406&amp;w=2">20011221 @stake advisory: Multiple overflow and format string vulnerabilities in in Microsoft SQL Server</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a122001-1.txt" adv="1" patch="1">A122001-1</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/700575">VU#700575</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3733" adv="1" patch="1">3733</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-060">MS01-060</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7724">mssql-text-message-bo(7724)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A83">oval:org.mitre.oval:def:83</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0543" seq="2001-0543" published="2001-09-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3183">3183</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-043">MS01-043</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6977">win-nntp-dos(6977)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A334">oval:org.mitre.oval:def:334</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0544" seq="2001-0544" published="2001-10-30" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-132.shtml">L-132</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3195">3195</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044">MS01-044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6983">iis-invalid-mime-header-dos(6983)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0545" seq="2001-0545" published="2001-10-30" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IIS 4.0 with URL redirection enabled allows remote attackers to cause a denial of service (crash) via a malformed request that specifies a length that is different than the actual length.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-132.shtml">L-132</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-044">MS01-044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6981">iis-url-redirection-dos(6981)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0546" seq="2001-0546" published="2001-09-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3196">3196</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-045">MS01-045</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6989">isa-h323-gatekeeper-dos(6989)</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0547" seq="2001-0547" published="2001-09-20" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3197">3197</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-045">MS01-045</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6990">isa-proxy-memory-leak-dos(6990)</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0548" seq="2001-0548" published="2001-08-14" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99598918914068&amp;w=2">20010724 NSFOCUS SA2001-04 : Solaris dtmail Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3081">3081</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6879">solaris-dtmail-bo(6879)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0549" seq="2001-0549" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/814187" adv="1" patch="1">VU#814187</ref>
      <ref source="CONFIRM" url="http://www.sarc.com/avcenter/security/Content/2001_07_20.html" adv="1">http://www.sarc.com/avcenter/security/Content/2001_07_20.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7013">liveupdate-obtain-proxy-password(7013)</ref>
    </refs>
    <vuln_soft>
      <prod name="liveupdate" vendor="symantec">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0550" seq="2001-0550" published="2001-11-30" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000442">CLA-2001:442</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-036-01">IMNX-2001-70-036-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100700363414799&amp;w=2">20011128 CORE-20011001: Wu-FTP glob heap corruption vulnerability</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-041.0.txt" adv="1" patch="1">CSSA-2001-041.0</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-33.html" adv="1" patch="1">CA-2001-33</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-087">DSA-087</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/886083" adv="1" patch="1">VU#886083</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-090.php3">MDKSA-2001:090</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_043_wuftpd_txt.html">SuSE-SA:2001:043</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-157.html" adv="1" patch="1">RHSA-2001:157</ref>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/180823">20010430 some ftpd implementations mishandle CWD ~{</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3581" adv="1" patch="1">3581</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-162">HPSBUX0107-162</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7611">wuftp-glob-heap-corruption(7611)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftpd-bsd" vendor="david_madore">
        <vers num="0.3.2"/>
        <vers num="0.3.3"/>
      </prod>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.5.0"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0551" seq="2001-0551" published="2001-05-22" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q2/0044.html" adv="1" patch="1">HPSBUX0105-151</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/860296" adv="1" patch="1">VU#860296</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5958">oval:org.mitre.oval:def:5958</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0552" seq="2001-0552" published="2001-09-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99201278704545&amp;w=2">20010608 HP Openview NNM6.1 ovactiond bin exploit</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-24.html" adv="1" patch="1">CA-2001-24</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/952171" adv="1" patch="1">VU#952171</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2845" adv="1" patch="1">2845</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="5.01"/>
        <vers num="6.1"/>
      </prod>
      <prod name="tivoli_netview" vendor="ibm">
        <vers num="5.0"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0553" seq="2001-0553" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html" adv="1" patch="1">20010720 URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-121.shtml">L-121</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/737451">VU#737451</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3078">3078</ref>
      <ref source="CONFIRM" url="http://www.ssh.com/products/ssh/exploit.cfm">http://www.ssh.com/products/ssh/exploit.cfm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6868">ssh-password-length-unauth-access(6868)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_shell" vendor="ssh">
        <vers num="3.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0554" seq="2001-0554" published="2001-08-14" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:49.telnetd.asc" adv="1" patch="1">FreeBSD-SA-01:49</ref>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-012.txt.asc">NetBSD-SA2001-012</ref>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010801-01-P">20010801-01-P</ref>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.10/CSSA-2001-SCO.10.txt">CSSA-2001-SCO.10</ref>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q4/0014.html">HPSBUX0110-172</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000413">CLA-2001:413</ref>
      <ref source="COMPAQ" url="http://ftp.support.compaq.com/patches/.new/html/SSRT0745U.shtml">SSRT0745U</ref>
      <ref source="IBM" url="http://online.securityfocus.com/advisories/3476">MSS-OAR-E01-2001:298</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/199496">20010725 Telnetd AYT overflow scanner</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/199541">20010725 SCO - Telnetd AYT overflow ?</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/203000">20010810 ADV/EXP: netkit &lt;=0.17 in.telnetd remote buffer overflow</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-030.0.txt">CSSA-2001-030.0</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-21.html" adv="1" patch="1">CA-2001-21</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-131.shtml">L-131</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/catos-telrcv-vuln-pub.shtml">20020129 Cisco CatOS Telnet Buffer Vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-070">DSA-070</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-075">DSA-075</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-068.php3">MDKSA-2001:068</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_029_nkitb_txt.html">SuSE-SA:2001:029</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-099.html">RHSA-2001:099</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-100.html">RHSA-2001:100</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197804" adv="1">20010718 multiple vendor telnet daemon vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3064" adv="1" patch="1">3064</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6875">telnetd-option-telrcv-bo(6875)</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="1.0"/>
        <vers num="5-1.2"/>
        <vers num="5-1.2.1"/>
        <vers num="5-1.2.2"/>
        <vers num="5_1.1"/>
        <vers num="5_1.1.1"/>
      </prod>
      <prod name="linux_netkit" vendor="netkit">
        <vers num="0.10"/>
        <vers num="0.11"/>
        <vers num="0.12"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.5.1"/>
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="5.1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0555" seq="2001-0555" published="2001-08-14" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a ..  (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0165.html" adv="1">20010613 ScreamingMedia SITEWare arbitrary file retrieval vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0166.html" adv="1">20010613 ScreamingMedia SITEWare source code disclosure vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/795707">VU#795707</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2869">2869</ref>
      <ref source="CONFIRM" url="http://www01.screamingmedia.com/en/security/sms1001.php" adv="1" patch="1">http://www01.screamingmedia.com/en/security/sms1001.php</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6689">siteware-dot-file-retrieval(6689)</ref>
    </refs>
    <vuln_soft>
      <prod name="siteware" vendor="screaming_media">
        <vers num="3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0556" seq="2001-0556" published="2001-08-22" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-053" adv="1" patch="1">DSA-053</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-042.php3" adv="1" patch="1">MDKSA-2001:042</ref>
      <ref source="CONFIRM" url="http://www.nedit.org/archives/develop/2001-Feb/0391.html">http://www.nedit.org/archives/develop/2001-Feb/0391.html</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_014_nedit.html">SuSE-SA:2001:14</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-061.html" adv="1" patch="1">RHSA-2001:061</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/180237">20010428 More nedit problems ? (was Re: PROGENY-SA-2001-10...)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2667" adv="1" patch="1">2667</ref>
    </refs>
    <vuln_soft>
      <prod name="nedit" vendor="nedit">
        <vers num="5.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0557" seq="2001-0557" published="2001-08-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0086.html" adv="1" patch="1">20010507 Advisory for Jana server</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/132099">VU#132099</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2703" adv="1" patch="1">2703</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6513">jana-server-directory-traversal(6513)</ref>
    </refs>
    <vuln_soft>
      <prod name="jana_web_server" vendor="t._hauck">
        <vers num="1.0j"/>
        <vers num="1.45"/>
        <vers num="1.46" prev="1"/>
        <vers num="2.0_beta_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0558" seq="2001-0558" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0086.html" adv="1" patch="1">20010507 Advisory for Jana server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2704">2704</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6521">jana-server-device-dos(6521)</ref>
    </refs>
    <vuln_soft>
      <prod name="jana_web_server" vendor="t._hauck">
        <vers num="1.45"/>
        <vers num="1.46"/>
        <vers num="2.0b2"/>
        <vers num="2.0beta1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0559" seq="2001-0559" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a local attacker to gain additional privileges when an editor is called to correct the error.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-054" adv="1">DSA-054</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-050.php3" adv="1" patch="1">MDKSA-2001:050</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_017_cron_txt.html">SuSE-SA:2001:17</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/183029" adv="1" patch="1">20010507 Vixie cron vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2687" adv="1" patch="1">2687</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6508">vixie-cron-gain-privileges(6508)</ref>
    </refs>
    <vuln_soft>
      <prod name="vixie_cron" vendor="paul_vixie">
        <vers num="3.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0560" seq="2001-0560" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0197.html" adv="1" patch="1">20010210 vixie cron possible local root compromise</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0066.html" adv="1" patch="1">20010220 Immunix OS Security update for vixie-cron</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-022.php3" adv="1" patch="1">MDKSA-2001:022</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-014.html" adv="1" patch="1">RHSA-2001:014</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17048&amp;apar=only">IY17048</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17261&amp;apar=only">IY17261</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6098">vixie-crontab-bo(6098)</ref>
    </refs>
    <vuln_soft>
      <prod name="vixie_cron" vendor="paul_vixie">
        <vers num="3.0.1.56" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0561" seq="2001-0561" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html" adv="1" patch="1">20010507 Advisory for A1Stats</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/471691">VU#471691</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2705" adv="1">2705</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6503">a1stats-dot-directory-traversal(6503)</ref>
    </refs>
    <vuln_soft>
      <prod name="a1stats" vendor="drummond_miles">
        <vers num="1.0"/>
        <vers num="1.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0562" seq="2001-0562" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html" adv="1" patch="1">20010507 Advisory for A1Stats</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2705" adv="1">2705</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6505">a1stats-a1admin-dos(6505)</ref>
    </refs>
    <vuln_soft>
      <prod name="a1stats" vendor="drummond_miles">
        <vers num="1.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0563" seq="2001-0563" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via large (> 160000 character) strings sent to port 23.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0049.html" adv="1">20010507 Advisory for Electrocomm 2.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2706" adv="1">2706</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6514">electrocomm-telnet-dos(6514)</ref>
    </refs>
    <vuln_soft>
      <prod name="electrocomm" vendor="electrosoft">
        <vers num="1.0"/>
        <vers num="2.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0564" seq="2001-0564" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker to create a denial of service via repeated failed logon attempts which temporarily locks the card.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="ftp://ftp.apcftp.com/hardware/webcard/firmware/sy/v310/install.txt">ftp://ftp.apcftp.com/hardware/webcard/firmware/sy/v310/install.txt</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0436.html" adv="1">20010225 APC web/snmp/telnet management card dos</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2430">2430</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6199">apc-telnet-dos(6199)</ref>
    </refs>
    <vuln_soft>
      <prod name="ap9606" vendor="apc">
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0565" seq="2001-0565" published="2001-08-14" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F' command line option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0016.html" adv="1" patch="1">20010502 Solaris mailx Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/184210">20010511 Solaris /usr/bin/mailx exploit (SPARC)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/446864">VU#446864</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2610">2610</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8246">solaris-mailx-f-bo(8246)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":sparc"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":sparc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6" edition=":sparc"/>
        <vers num="7.0" edition=":sparc"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":sparc"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0566" seq="2001-0566" published="2001-08-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP  is disabled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0040.html">20010503 Cisco Catalyst 2900XL crashes with empty UDP packet when SNMP is disabled.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6515">cisco-catalyst-udp-dos(6515)</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_2900" vendor="cisco">
        <vers num="xl"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0567" seq="2001-0567" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClass permission mappings for objects and methods in the ZClass.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000407">CLA-2001:407</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-055" adv="1">DSA-055</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-049.php3" adv="1">MDKSA-2001:049</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-065.html" adv="1" patch="1">RHSA-2001:065</ref>
      <ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_2001-05-01/security_alert">http://www.zope.org/Products/Zope/Hotfix_2001-05-01/security_alert</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6958">zope-zclass-gain-privileges(6958)</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0568" seq="2001-0568" published="2001-08-22" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000382">CLA-2001:382</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-043" adv="1" patch="1">DSA-043</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-025.php3" patch="1">MDKSA-2001:025</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-021.html" adv="1" patch="1">RHSA-2001:021</ref>
      <ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23" adv="1" patch="1">http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="2.3.1_b1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0569" seq="2001-0569" published="2001-08-22" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000382">CLA-2001:382</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-043" adv="1" patch="1">DSA-043</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-025.php3" patch="1">MDKSA-2001:025</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-021.html" adv="1" patch="1">RHSA-2001:021</ref>
      <ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23" adv="1" patch="1">http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="2.3.1_b1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0570" seq="2001-0570" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99014300904714&amp;w=2">20010517 Immunix OS Security update for minicom</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-016.0.txt" adv="1" patch="1">CSSA-2001-016.0</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-067.html" adv="1" patch="1">RHSA-2001:067</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/181922">20010503 minicom exploit</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6498">minicom-xmodem-format-string(6498)</ref>
    </refs>
    <vuln_soft>
      <prod name="minicom" vendor="minicom">
        <vers num="1.83.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0571" seq="2001-0571" published="2001-08-22" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0382.html">20010406 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98538867727489&amp;w=2">20010323 Elron IM Products Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98567864203963&amp;w=2">20010326 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2519" adv="1" patch="1">2519</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2520" adv="1" patch="1">2520</ref>
    </refs>
    <vuln_soft>
      <prod name="im_anti_virus" vendor="elron">
        <vers num="3.0.3"/>
      </prod>
      <prod name="im_message_inspector" vendor="elron">
        <vers num="3.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0572" seq="2001-0572" published="2001-08-22" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0225.html" adv="1" patch="1">20010318 Passive Analysis of SSH (Secure Shell) Traffic</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000391" adv="1">CLA-2001:391</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/596827">VU#596827</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-033.php3" adv="1" patch="1">MDKSA-2001:033</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-033.html" adv="1" patch="1">RHSA-2001:033</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="4.5"/>
      </prod>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0573" seq="2001-0573" published="2001-08-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2) lslv in a certain directory that is under the user's control, which cause lsfs to access the programs in that directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/aix/2001-q2/0000.html" adv="1" patch="1">IY16909</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/123651">VU#123651</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7007">aix-lsfs-path(7007)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0574" seq="2001-0574" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0046.html" adv="1" patch="1">20010507 Advisory for MP3Mystic</ref>
      <ref source="CONFIRM" url="http://mp3mystic.com/mp3mystic/news.phtml" adv="1" patch="1">http://mp3mystic.com/mp3mystic/news.phtml</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2699" adv="1" patch="1">2699</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6504">mp3mystic-dot-directory-traversal(6504)</ref>
    </refs>
    <vuln_soft>
      <prod name="mp3mystic" vendor="jason_rahaim">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0575" seq="2001-0575" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0404.html" adv="1" patch="1">20010327 SCO 5.0.6 issues (lpshut)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6290">sco-openserver-lpshut-bo(6290)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0576" seq="2001-0576" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a  local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0407.html" adv="1" patch="1">20010327 SCO 5.0.6 issues (lpusers)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6292">sco-openserver-lpusers-bo(6292)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0577" seq="2001-0577" published="2001-08-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0410.html" adv="1" patch="1">20010327 SCO 5.0.6 issues (recon)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6289">sco-openserver-recon-bo(6289)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0578" seq="2001-0578" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0416.html" adv="1" patch="1">20010327 SCO 5.0.6 issues (lpforms)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6293">sco-openserver-lpforms-bo(6293)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0579" seq="2001-0579" published="2001-08-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0421.html" adv="1" patch="1">20010327 SCO 5.0.6 issues (lpadmin)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6291">sco-openserver-lpadmin-bo(6291)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0580" seq="2001-0580" published="2001-08-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0050.html" adv="1" patch="1">200105007 Advisory for Vdns</ref>
    </refs>
    <vuln_soft>
      <prod name="dsl_vdns" vendor="hughes_technologies">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0581" seq="2001-0581" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0051.html" adv="1">20010507 Advisory for Spynet Chat</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2701" adv="1" patch="1">2701</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6509">spynet-connection-dos(6509)</ref>
    </refs>
    <vuln_soft>
      <prod name="spynet_chat" vendor="spytech">
        <vers num="6.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0582" seq="2001-0582" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0036.html" adv="1" patch="1">20010503 Vulnerabilities in CrushFTP Server</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/110803">VU#110803</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6495">crushftp-directory-traversal(6495)</ref>
    </refs>
    <vuln_soft>
      <prod name="crushftp_ftp_server" vendor="ben_spink">
        <vers num="2.1.4"/>
        <vers num="2.1.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0583" seq="2001-0583" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Alt-N Technologies MDaemon 3.5.4 allows a remote attacker to create a denial of service via the URL request of a MS-DOS device (such as GET /aux) to (1) the Worldclient service at port 3000, or (2) the Webconfig service at port 3001.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0188.html" adv="1" patch="1">20010315 def-2001-11: MDaemon 3.5.4 Dos-Device DoS</ref>
      <ref source="CONFIRM" url="http://ftp1.deerfield.com/pub/mdaemon/Archive/3.5.6/">http://ftp1.deerfield.com/pub/mdaemon/Archive/3.5.6/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6240">mdaemon-webservices-dos(6240)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="3.5.4" edition=":pro"/>
        <vers num="3.5.4" edition=":standard"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0584" seq="2001-0584" published="2001-08-22" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0365.html" adv="1" patch="1">20010325 MDaemon IMAP Denial Of Service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2508" adv="1">2508</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6279">mdaemon-imap-command-dos(6279)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdaemon" vendor="alt-n">
        <vers num="3.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0585" seq="2001-0585" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Gordano NTMail 6.0.3c allows a remote attacker to create a denial of service via a long (>= 255 characters) URL request to port 8000 or port 9000.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0248.html" adv="1" patch="1">20010320 def-2001-13: NTMail Web Services DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2494" adv="1" patch="1">2494</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6249">ntmail-long-url-dos(6249)</ref>
    </refs>
    <vuln_soft>
      <prod name="ntmail" vendor="gordano">
        <vers num="6.0.3c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0586" seq="2001-0586" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for ScanMail via a combination of unprotected registry keys and weakly encrypted passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2001-q1/0049.html" adv="1" patch="1">20010330 STAT Security Advisory: Trend Micro's ScanMail for Exchange store s passwords in registry unprotected</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6311">scanmail-reveals-credentials(6311)</ref>
    </refs>
    <vuln_soft>
      <prod name="scanmail_exchange" vendor="trend_micro">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0587" seq="2001-0587" published="2001-08-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">deliver program in MMDF 2.43.3b in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0418.html" adv="1" patch="1">20010327 SCO 5.0.6 MMDF issues (deliver)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2583">2583</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6302">sco-openserver-deliver-bo(6302)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0588" seq="2001-0588" published="2001-08-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0417.html" adv="1" patch="1">20010327 SCO 5.0.6 MMDF issues (sendmail 8.9.3)</ref>
      <ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html">20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0589" seq="2001-0589" published="2001-08-22" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0375.html" adv="1" patch="1">20010326 Netscreen: DMZ Network Receives Some "Denied" Traffic</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2523" adv="1" patch="1">2523</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6317">netscreen-screenos-bypass-firewall(6317)</ref>
    </refs>
    <vuln_soft>
      <prod name="netscreen_screenos" vendor="juniper">
        <vers num="1.64"/>
        <vers num="1.66"/>
        <vers num="2.1"/>
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0590" seq="2001-0590" published="2001-08-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0031.html" adv="1">20010403 Re: Tomcat may reveal script source code by URL trickery</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-004">HPSBTL0112-004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6971">jakarta-tomcat-jsp-source(6971)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0591" seq="2001-0591" published="2001-08-22" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0239.html" adv="1" patch="1">20010212 Patch for Potential Vulnerability in the execution of JSPs outside doc_root</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2286" adv="1" patch="1">2286</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5986">oracle-handlers-directory-traversal(5986)</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="1.0.2"/>
      </prod>
      <prod name="jsp" vendor="oracle">
        <vers num="1.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0592" seq="2001-0592" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Watchguard Firebox II prior to 4.6 allows a remote attacker to create a denial of service in the kernel via a large stream (>10,000) of malformed ICMP or TCP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0054.html" adv="1" patch="1">20010405 def-2001-18: Watchguard Firebox II Kernel DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6327">firebox-kernel-dos(6327)</ref>
    </refs>
    <vuln_soft>
      <prod name="firebox_ii" vendor="watchguard">
        <vers num="4.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0593" seq="2001-0593" published="2001-08-22" modified="2018-11-16" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Anaconda Partners Clipper 3.3 and earlier allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the template parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://anacondapartners.com/cgi-local/apexec.pl?template=ap_releasenotestemplate.html&amp;f1=ap_af_updates_menu&amp;f2=ap_af_releasenotes_clip">http://anacondapartners.com/cgi-local/apexec.pl?template=ap_releasenotestemplate.html&amp;f1=ap_af_updates_menu&amp;f2=ap_af_releasenotes_clip</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0395.html" adv="1" patch="1">20010327 advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2512" adv="1">2512</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6286">anaconda-clipper-directory-traversal(6286)</ref>
    </refs>
    <vuln_soft>
      <prod name="clipper" vendor="anaconda_partners">
        <vers num="3.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0594" seq="2001-0594" published="2001-08-02" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0140.html" adv="1" patch="1">20010409 Solaris kcms_configure vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2558" adv="1">2558</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6359">solaris-kcms-command-bo(6359)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A65">oval:org.mitre.oval:def:65</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7">oval:org.mitre.oval:def:7</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0595" seq="2001-0595" published="2001-08-02" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands via the KCMS_PROFILES environment variable, e.g. as demonstrated using the kcms_configure program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0203.html" adv="1">20010411 [LSD] Solaris kcsSUNWIOsolf.so and dtsession vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2605">2605</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6365">solaris-kcssunwiosolf-bo(6365)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0596" seq="2001-0596" published="2001-08-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000393">CLA-2001:393</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-014-01">IMNX-2001-70-014-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98685237415117&amp;w=2">20010409 Netscape 4.76 gif comment flaw</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-051" adv="1" patch="1">DSA-051</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-046.html" adv="1" patch="1">RHSA-2001:046</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2637">2637</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6344">netscape-javascript-access-data(6344)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.77" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0597" seq="2001-0597" published="2001-08-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack.  This attack is made feasible by STRIP's use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password 'search space'.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0169.html" adv="1" patch="1">20010410 Catastrophic failure of Strip password generation.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2567" adv="1" patch="1">2567</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6362">strip-weak-passwords(6362)</ref>
    </refs>
    <vuln_soft>
      <prod name="strip" vendor="zetetic_enterprises">
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0598" seq="2001-0598" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Symantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configuration Server on port 1347, which triggers an error that is not properly handled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0175.html" adv="1" patch="1">20010411 def-2001-21: Ghost Multiple DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2570" adv="1" patch="1">2570</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6357">ghost-configuration-server-dos(6357)</ref>
    </refs>
    <vuln_soft>
      <prod name="norton_ghost" vendor="symantec">
        <vers num="6.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0599" seq="2001-0599" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sybase Adaptive Server Anywhere Database Engine 6.0.3.2747 and earlier as included with Symantec Ghost 6.5 allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to port 2638.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0175.html" adv="1" patch="1">20010411 def-2001-21: Ghost Multiple DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2572" adv="1" patch="1">2572</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6356">ghost-database-engine-dos(6356)</ref>
    </refs>
    <vuln_soft>
      <prod name="adaptive_server_anywhere" vendor="sybase">
        <vers num="6.0.3.2747" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0600" seq="2001-0600" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated URL requests with the same HTTP headers, such as (1) Accept, (2) Accept-Charset, (3) Accept-Encoding, (4) Accept-Language, and (5) Content-Type.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" adv="1" patch="1">20010411 def-2001-20: Lotus Domino Multiple DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6347">lotus-domino-header-dos(6347)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_r5_server" vendor="lotus">
        <vers num="5.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0601" seq="2001-0601" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via HTTP requests containing certain combinations of UNICODE characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" adv="1">20010411 def-2001-20: Lotus Domino Multiple DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6349">lotus-domino-unicode-dos(6349)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_r5_server" vendor="lotus">
        <vers num="5.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0602" seq="2001-0602" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated (>400) URL requests for DOS devices.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" adv="1" patch="1">20010411 def-2001-20: Lotus Domino Multiple DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6348">lotus-domino-device-dos(6348)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_r5_server" vendor="lotus">
        <vers num="5.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0603" seq="2001-0603" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" adv="1" patch="1">20010411 def-2001-20: Lotus Domino Multiple DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6350">lotus-domino-corba-dos(6350)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_r5_server" vendor="lotus">
        <vers num="5.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0604" seq="2001-0604" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of '/' characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html" adv="1" patch="1">20010411 def-2001-20: Lotus Domino Multiple DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6351">lotus-domino-url-dos(6351)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_r5_server" vendor="lotus">
        <vers num="5.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0605" seq="2001-0605" published="2001-08-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Headlight Software MyGetright prior to 1.0b allows a remote attacker to upload and/or overwrite arbitrary files via a malicious .dld (skins-data) file which contains long strings of random data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98321819112158&amp;w=2">20010226 My Getright Unsupervised File Download Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="mygetright" vendor="headlight_software">
        <vers num="1.0b" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0606" seq="2001-0606" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0041.html" adv="1" patch="1">HPSBUX0102-139</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6110">hp-virtualvault-iws-dos(6110)</ref>
    </refs>
    <vuln_soft>
      <prod name="virtualvault" vendor="hp">
        <vers num="4.0"/>
      </prod>
      <prod name="iplanet_web_server" vendor="sun">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0607" seq="2001-0607" published="2001-08-22" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0080.html" adv="1" patch="1">HPSBUX0103-145</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5621">oval:org.mitre.oval:def:5621</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0608" seq="2001-0608" published="2001-08-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">HP architected interface facility (AIF) as includes with MPE/iX 5.5 through 6.5 running on a HP3000 allows an attacker to gain additional privileges and gain access to databases via the AIF - AIFCHANGELOGON program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0087.html" adv="1" patch="1">HPSBMP0103-011</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/895496">VU#895496</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6951">hp-aif-gain-privileges(6951)</ref>
    </refs>
    <vuln_soft>
      <prod name="mpe" vendor="hp">
        <vers num="6.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0609" seq="2001-0609" published="2001-08-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0202.html" adv="1" patch="1">20010411 CFINGERD remote vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2576" adv="1" patch="1">2576</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6364">cfingerd-remote-format-string(6364)</ref>
    </refs>
    <vuln_soft>
      <prod name="cfingerd" vendor="infodrom">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0610" seq="2001-0610" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0336.html">20010418 Insecure directory handling in KFM file manager</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6428">kfm-tmpfile-symlink(6428)</ref>
    </refs>
    <vuln_soft>
      <prod name="kde" vendor="kde">
        <vers num="1.x"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="7.0" edition=":ppc"/>
        <vers num="7.0" edition=":sparc"/>
        <vers num="7.0" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0611" seq="2001-0611" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Becky! 2.00.05 and earlier can allow a remote attacker to gain additional privileges via a buffer overflow attack on long messages without newline characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0089.html" adv="1" patch="1">20010514 Becky! 2.00.05 Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2723" adv="1" patch="1">2723</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6531">becky-mail-message-bo(6531)</ref>
    </refs>
    <vuln_soft>
      <prod name="becky_internet_mail" vendor="rimarts_inc.">
        <vers num="1.26.3"/>
        <vers num="1.26.4"/>
        <vers num="1.26.5"/>
        <vers num="2.0.3"/>
        <vers num="2.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0612" seq="2001-0612" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0158.html" adv="1" patch="1">20010516 Remote Desktop DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2726" adv="1" patch="1">2726</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6547">remote-desktop-dos(6547)</ref>
    </refs>
    <vuln_soft>
      <prod name="remote_desktop_32" vendor="mcafee">
        <vers num="2.1.2"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0613" seq="2001-0613" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0131.html" adv="1">20010515 OmniHTTPd Pro Denial of Service Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2730" adv="1">2730</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6540">omnihttpd-post-dos(6540)</ref>
    </refs>
    <vuln_soft>
      <prod name="omnihttpd" vendor="omnicron">
        <vers num="2.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0614" seq="2001-0614" published="2001-08-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98991352402073&amp;w=2">20010514 def-2001-25: Carello E-Commerce Arbitrary Command Execution</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6532">carello-url-code-execution(6532)</ref>
    </refs>
    <vuln_soft>
      <prod name="e-commerce" vendor="carello">
        <vers num="1.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0615" seq="2001-0615" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0241.html" adv="1" patch="1">20010525 Advisory for Freestyle Chat server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2776" adv="1" patch="1">2776</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6601">freestyle-chat-directory-traversal(6601)</ref>
    </refs>
    <vuln_soft>
      <prod name="freestyle_chat" vendor="faust_informatics">
        <vers num="4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0616" seq="2001-0616" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0241.html" adv="1" patch="1">20010525 Advisory for Freestyle Chat server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2777" adv="1" patch="1">2777</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6602">freestyle-chat-device-dos(6602)</ref>
    </refs>
    <vuln_soft>
      <prod name="freestyle_chat" vendor="faust_informatics">
        <vers num="4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0617" seq="2001-0617" published="2001-08-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the 'Virtual Server' enabled can allow a remote attacker to gain access to mapped services even though the single portmappings may be disabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0125.html" adv="1" patch="1">20010514 Cable-Router AR220e Portmapper Security-Flaw</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6560">telesyn-portmapper-access-services(6560)</ref>
    </refs>
    <vuln_soft>
      <prod name="at-ar220e" vendor="alliedtelesyn">
        <vers num="1.08a" edition="rc14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0618" seq="2001-0618" published="2001-08-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key.  Since the SSID occurs in the clear during communications, a remote attacker could determine the WEP key and decrypt RG-1000 traffic.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0020.html" adv="1">20010402 RG-1000 802.11 Residential Gateway default WEP key disclosure flaw</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6328">orinoco-rg1000-wep-key(6328)</ref>
    </refs>
    <vuln_soft>
      <prod name="orinoco_rg-1000" vendor="lucent">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0619" seq="2001-0619" published="2001-08-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to.  The 'Network Name' or SSID, which is used as a shared secret to join the network, is transmitted in the clear.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0015.html" adv="1">20010402 Design Flaw in Lucent/Orinoco 802.11 proprietary access control- closed network</ref>
    </refs>
    <vuln_soft>
      <prod name="orinoco" vendor="lucent">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0620" seq="2001-0620" published="2001-08-02" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0320.html">20010418 iplanet calendar server 5.0p2 exposes Netscape Admin Server master password</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6402">iplanet-calendar-plaintext-password(6402)</ref>
    </refs>
    <vuln_soft>
      <prod name="calendar_server" vendor="iplanet">
        <vers num="5.0p2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0621" seq="2001-0621" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The FTP server on Cisco Content Service 11000 series switches (CSS) before WebNS 4.01B23s and WebNS 4.10B13s allows an attacker who is an FTP user to read and write arbitrary files via GET or PUT commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-085.shtml">L-085</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/arrowpoint-ftp-pub.shtml" adv="1" patch="1">20010517 Cisco Content Service Switch 11000 Series FTP Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2745">2745</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6557">cisco-css-ftp-commands(6557)</ref>
    </refs>
    <vuln_soft>
      <prod name="content_services_switch_11000" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0622" seq="2001-0622" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The web management service on Cisco Content Service series 11000 switches (CSS) before WebNS 4.01B29s or WebNS 4.10B17s allows a remote attacker to gain additional privileges by directly requesting the web management URL instead of navigating through the interface.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/arrowpoint-webmgmt-vuln-pub.shtml" adv="1" patch="1">20010531 Cisco Content Service Switch 11000 Series Web Management Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2806">2806</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6631">cisco-css-web-management(6631)</ref>
    </refs>
    <vuln_soft>
      <prod name="content_services_switch_11000" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0623" seq="2001-0623" published="2001-08-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-050">DSA-050</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-052" adv="1" patch="1">DSA-052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6430">saft-sendfiled-execute-code(6430)</ref>
    </refs>
    <vuln_soft>
      <prod name="sendfile" vendor="sendfile">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0624" seq="2001-0624" published="2001-08-02" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0266.html" adv="1">20010421 QNX FIle Read Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6437">qnx-fat-file-read(6437)</ref>
    </refs>
    <vuln_soft>
      <prod name="qnx" vendor="qnx">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0625" seq="2001-0625" published="2001-08-22" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log .</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0245.html" adv="1">20010525 Security Bug in InoculateIT for Linux (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2778">2778</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6607">inoculateit-ftpdownload-symlink(6607)</ref>
    </refs>
    <vuln_soft>
      <prod name="inoculateit" vendor="ca">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0626" seq="2001-0626" published="2001-08-22" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0236.html" adv="1">20010316 WebServer Pro All Version Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2488" adv="1">2488</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3839">website-pro-dir-path(3839)</ref>
    </refs>
    <vuln_soft>
      <prod name="website_professional" vendor="oreilly">
        <vers num="2.5.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0627" seq="2001-0627" published="2001-08-22" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.17/CSSA-2001-SCO.17.txt">CSSA-2001-SCO.17</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0220.html" adv="1">20010522 [SRT2001-09] - vi and crontab -e /tmp issues</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/747736">VU#747736</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2752" adv="1">2752</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6588">sco-openserver-vi-symlink(6588)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0628" seq="2001-0628" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q274/2/28.asp" adv="1" patch="1">Q274228</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2760" adv="1" patch="1">2760</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6614">word-asd-macro-execution(6614)</ref>
    </refs>
    <vuln_soft>
      <prod name="word" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0629" seq="2001-0629" published="2001-08-14" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP Event Correlation Service (ecsd) as included with OpenView Network Node  Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0226.html" adv="1" patch="1">20010523 HP OpenView NNM v6.1 buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2761" adv="1" patch="1">2761</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0107-158">HPSBUX0107-158</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6582">openview-nnm-ecsd-bo(6582)</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0630" seq="2001-0630" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0231.html" adv="1" patch="1">20010523 Vulnerability in viewsrc.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2762" adv="1" patch="1">2762</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6583">viewsrc-cgi-view-files(6583)</ref>
    </refs>
    <vuln_soft>
      <prod name="source_viewer" vendor="mimanet">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0631" seq="2001-0631" published="2001-08-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '&lt;@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0376.html" adv="1">20010221 FirstClass Internetgateway "stupidity"</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0440.html" adv="1">20010226 Re: [Fwd: FirstClass Internetgateway "stupidity"]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2423">2423</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6192">centrinity-firstclass-email-spoofing(6192)</ref>
    </refs>
    <vuln_soft>
      <prod name="centrinity_firstclass" vendor="centrinity">
        <vers num="5.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0632" seq="2001-0632" published="2001-08-22" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html" adv="1">20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html" adv="1" patch="1">20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="chilisoft" vendor="sun">
        <vers num="3.5.2"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0633" seq="2001-0633" published="2001-08-22" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html" adv="1">20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html" adv="1" patch="1">20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="chilisoft" vendor="sun">
        <vers num="3.5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0634" seq="2001-0634" published="2001-08-22" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Sun Chili!Soft ASP has weak permissions on various configuration files, which allows a local attacker to gain additional privileges and create a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html" adv="1" patch="1">20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html" adv="1" patch="1">20010226 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2409">2409</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6176">chilisoft-asp-license-dos(6176)</ref>
    </refs>
    <vuln_soft>
      <prod name="chilisoft" vendor="sun">
        <vers num="3.5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0635" seq="2001-0635" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-058.html" adv="1" patch="1">RHSA-2001:058</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6493">mount-swap-world-readable(6493)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0636" seq="2001-0636" published="2001-09-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in the Knowledge Browser component in SilentRunner 2.0 and 2.0.1.  NOTE: It is highly likely that this candidate will be split into multiple candidates.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise91.php" adv="1">20010806 Multiple Buffer Overflow Vulnerabilities in Raytheon SilentRunner</ref>
    </refs>
    <vuln_soft>
      <prod name="silentrunner" vendor="raytheon">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0641" seq="2001-0641" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0087.html" adv="1">20010513 RH 7.0:/usr/bin/man exploit: gid man + more</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_019_man_txt.html">SuSE-SA:2001:019</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-069.html" adv="1" patch="1">RHSA-2001:069</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/190136">20010612 man 1.5h10 + man 1.5i-4 exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2711" adv="1" patch="1">2711</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6530">man-s-bo(6530)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0642" seq="2001-0642" published="2001-09-20" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0078.html" adv="1">20010511 [eyeonsecurity.net] Incredimail allows automatic over writing offiles on your hard disk</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6529">incredimail-dot-overwrite-files(6529)</ref>
    </refs>
    <vuln_soft>
      <prod name="incredimail" vendor="incredimail">
        <vers num="1400185" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0643" seq="2001-0643" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://vil.nai.com/vil/virusSummary.asp?virus_k=99048" adv="1" patch="1">http://vil.nai.com/vil/virusSummary.asp?virus_k=99048</ref>
      <ref source="MISC" url="http://www.guninski.com/clsidext.html">http://www.guninski.com/clsidext.html</ref>
      <ref source="MISC" url="http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html" adv="1" patch="1">http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176909" adv="1" patch="1">20010416 Double clicking on innocent looking files may be dangerous</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2612">2612</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6426">ie-clsid-execute-files(6426)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0644" seq="2001-0644" published="2001-09-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/184751" adv="1" patch="1">20010515 Rumpus FTP DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2718" adv="1">2718</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6543">rumpus-plaintext-passwords(6543)</ref>
    </refs>
    <vuln_soft>
      <prod name="rumpus_ftp_server" vendor="maxum_development_corporation">
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="2.0.3_dev_3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0645" seq="2001-0645" published="2001-09-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0097.html" adv="1" patch="1">20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x password restrictions</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0098.html" adv="1">20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x database configuration</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/508387">VU#508387</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6537">netprowler-default-management-password(6537)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6539">netprowler-default-odbc-password(6539)</ref>
    </refs>
    <vuln_soft>
      <prod name="netprowler" vendor="axent">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0646" seq="2001-0646" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/184751" adv="1" patch="1">20010515 Rumpus FTP DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2716" adv="1" patch="1">2716</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6542">rumpus-long-directory-dos(6542)</ref>
    </refs>
    <vuln_soft>
      <prod name="rumpus_ftp_server" vendor="maxum_development_corporation">
        <vers num="1.3.2"/>
        <vers num="1.3.4"/>
        <vers num="2.0.3dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0647" seq="2001-0647" published="2001-08-06" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/165658">20010227 Orange Web Server v2.1 DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2432" adv="1">2432</ref>
    </refs>
    <vuln_soft>
      <prod name="orange_web_server" vendor="orange_software">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0648" seq="2001-0648" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/184215" adv="1" patch="1">20010508 security hole in os groupware suite PHProjekt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2702" adv="1" patch="1">2702</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6522">phprojekt-dot-directory-traversal(6522)</ref>
    </refs>
    <vuln_soft>
      <prod name="phprojekt" vendor="phprojekt">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0649" seq="2001-0649" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/184548" adv="1">20010510 Personal Web Sharing remote stop</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6536">macos-web-sharing-dos(6536)</ref>
    </refs>
    <vuln_soft>
      <prod name="personal_web_sharing" vendor="apple">
        <vers num="1.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0650" seq="2001-0650" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-082.shtml">L-082</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/ios-bgp-attr-corruption-pub.shtml" adv="1" patch="1">20010510 Cisco IOS BGP Attribute Corruption Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/106392" adv="1" patch="1">VU#106392</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2733">2733</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6566">cisco-ios-bgp-dos(6566)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.2"/>
        <vers num="11.3"/>
        <vers num="12.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0652" seq="2001-0652" published="2001-10-30" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99745571104126&amp;w=2">20010810 NSFOCUS SA2001-05 : Solaris Xlock Heap Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3160">3160</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6967">solaris-xlock-bo(6967)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10">oval:org.mitre.oval:def:10</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A131">oval:org.mitre.oval:def:131</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0653" seq="2001-0653" published="2001-09-20" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privileges via a large value in the 'category' part of debugger (-d) command line arguments, which is interpreted as a negative number.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-017.txt.asc">NetBSD-SA2001-017</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000412">CLA-2001:412</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-032-01">IMNX-2001-70-032-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99841063100516&amp;w=2">20010821 *ALERT* UPDATED BID 3163 (URGENCY 6.58): Sendmail Debugger Arbitrary Code Execution Vulnerability (fwd)</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-106.html">RHSA-2001:106</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-032.0.txt">CSSA-2001-032.0</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-133.shtml">L-133</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-075.php3">MDKSA-2001:075</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_028_sendmail_txt.html">SuSE-SA:2001:028</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3163" adv="1" patch="1">3163</ref>
      <ref source="CONFIRM" url="http://www.sendmail.org/8.11.html">http://www.sendmail.org/8.11.html</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-007">HPSBTL0112-007</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7016">sendmail-debug-signed-int-overflow(7016)</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.11.0"/>
        <vers num="8.11.1"/>
        <vers num="8.11.2"/>
        <vers num="8.11.3"/>
        <vers num="8.11.4"/>
        <vers num="8.11.5"/>
        <vers num="8.12" edition="beta10"/>
        <vers num="8.12" edition="beta12"/>
        <vers num="8.12" edition="beta16"/>
        <vers num="8.12" edition="beta5"/>
        <vers num="8.12" edition="beta7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0654" seq="2001-0654" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0655" seq="2001-0655" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0656" seq="2001-0656" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0657" seq="2001-0657" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0658" seq="2001-0658" published="2001-09-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3198">3198</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-045">MS01-045</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6991">isa-cross-site-scripting(6991)</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0659" seq="2001-0659" published="2001-09-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in IrDA driver providing infrared data exchange on Windows 2000 allows attackers who are physically close to the machine to cause a denial of service (reboot) via a malformed IrDA packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/209385">20010821 IrDA semiremote vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3215">3215</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-046">MS01-046</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7008">win2k-irda-dos(7008)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0660" seq="2001-0660" published="2001-10-30" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q307/1/95.ASP" adv="1" patch="1">Q307195</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3301">3301</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-047">MS01-047</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7089">exchange-owa-obtain-addresses(7089)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5" prev="1" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0662" seq="2001-0662" published="2001-10-30" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-142.shtml">L-142</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3313">3313</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-048">MS01-048</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7105">winnt-rpc-endpoint-dos(7105)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0663" seq="2001-0663" published="2001-12-06" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3445">3445</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-052">MS01-052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7302">win-rdp-packet-dos(7302)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0664" seq="2001-0664" published="2001-10-30" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100281551611595&amp;w=2">20011011 Serious security Flaw in Microsoft Internet Explorer - Zone Spoofing</ref>
      <ref source="MISC" url="http://morph3us.org/blog/?p=31">http://morph3us.org/blog/?p=31</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3420">3420</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051">MS01-051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7258">ie-incorrect-security-zone(7258)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.01"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0665" seq="2001-0665" published="2001-10-30" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP Request Encoding vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3421">3421</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051">MS01-051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7259">ie-url-http-requests(7259)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6" prev="1" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0666" seq="2001-0666" published="2001-10-30" modified="2018-10-12" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3368">3368</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-049">MS01-049</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7168">exchange-owa-folder-request-dos(7168)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0667" seq="2001-0667" published="2001-10-30" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-024.shtml">M-024</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/952611">VU#952611</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-051">MS01-051</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7260">ie-telnet-command-execution-variant(7260)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6" prev="1" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0668" seq="2001-0668" published="2001-09-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q3/0047.html">HPSBUX0108-163</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-30.html">CA-2001-30</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-134.shtml">L-134</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/966075">VU#966075</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3240">3240</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise93.php" adv="1" patch="1">20010827 Remote Buffer Overflow Vulnerability in HP-UX Line Printer Daemon</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6811">hpux-rlpd-bo(6811)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0669" seq="2001-0669" published="2001-10-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99972950200602&amp;w=2">20010905 %u encoding IDS bypass vulnerability</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml" adv="1" patch="1">20010905 Cisco Secure Intrusion Detection System Signature Obfuscation Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/548515">VU#548515</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3292">3292</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise95.php" adv="1" patch="1">20010905 Multiple Vendor IDS Unicode Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_6000_intrusion_detection_system_module" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="secure_intrusion_detection_system" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="realsecure_network_sensor" vendor="iss">
        <vers num="5.x"/>
        <vers num="6.x"/>
      </prod>
      <prod name="realsecure_server_sensor" vendor="iss">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
      <prod name="snort" vendor="snort">
        <vers num="1.8.1"/>
      </prod>
      <prod name="dragon" vendor="enterasys">
        <vers num="4.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0670" seq="2001-0670" published="2001-10-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-018.txt.asc">NetBSD-SA2001-018</ref>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.20/CSSA-2001-SCO.20.txt" patch="1">CSSA-2001-SCO.20</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-30.html">CA-2001-30</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/274043">VU#274043</ref>
      <ref source="OPENBSD" url="http://www.openbsd.com/errata28.html" patch="1">20010829</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-147.html">RHSA-2001:147</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3252">3252</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise94.php" adv="1" patch="1">20010829 Remote Buffer Overflow Vulnerability in BSD Line Printer Daemon</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7046">bsd-lpd-bo(7046)</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd" vendor="bsd">
        <vers num="4.1" prev="1"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.3" prev="1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5.1" prev="1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0671" seq="2001-0671" published="2001-12-06" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-30.html" adv="1" patch="1">CA-2001-30</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/388183" adv="1" patch="1">VU#388183</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/466239" adv="1" patch="1">VU#466239</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/722143" adv="1" patch="1">VU#722143</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0674" seq="2001-0674" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a hexadecimal encoded dot-dot attack (eg. http://www.server.com/%2e%2e/%2e%2e) in an HTTP URL request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.robtex.com/viking/bugs.htm" adv="1" patch="1">http://www.robtex.com/viking/bugs.htm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/177231" adv="1" patch="1">20010417 Advisory for Viking</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6394">viking-hex-directory-traversal(6394)</ref>
    </refs>
    <vuln_soft>
      <prod name="viking_server" vendor="robtex">
        <vers num="1.0.4"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.7_build381" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0675" seq="2001-0675" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return &lt;CR> that is not followed by a line feed &lt;LF>.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0345.html" adv="1">20010418 SECURITY.NNOV: The Bat! &lt;cr> bug</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0381.html" adv="1">20010421 Re: SECURITY.NNOV: The Bat! &lt;cr> bug</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0410.html" adv="1">20010423 Re: SECURITY.NNOV: The Bat! &lt;cr> bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2636">2636</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6423">thebat-pop3-dos(6423)</ref>
    </refs>
    <vuln_soft>
      <prod name="the_bat" vendor="ritlabs">
        <vers num="1.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0676" seq="2001-0676" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Rit Research Labs The Bat! 1.48f and earlier allows a remote attacker to create arbitrary files via a "dot dot" attack in the filename for an attachment.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/154359" adv="1" patch="1">20010104 SECURITY.NNOV advisory - The Bat! directory traversal (public release)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5871">thebat-attachment-directory-traversal(5871)</ref>
    </refs>
    <vuln_soft>
      <prod name="the_bat" vendor="ritlabs">
        <vers num="1.48f" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0677" seq="2001-0677" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Eudora 5.0.2 allows a remote attacker to read arbitrary files via an email with the path of the target file in the "Attachment Converted" MIME header, which sends the file when the email is forwarded to the attacker by the user.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/177369" adv="1">20010418 Eudora file leakage problem (still)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2616">2616</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6431">eudora-plain-text-attachment(6431)</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0678" seq="2001-0678" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A buffer overflow in reggo.dll file used by Trend Micro InterScan VirusWall prior to 3.51 build 1349 for Windows NT 3.5 and InterScan WebManager 1.2 allows a local attacker to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/185383" adv="1">20010519 TrendMicro Interscan VirusWall RegGo.dll BOf</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6575">interscan-reggo-bo(6575)</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.51"/>
      </prod>
      <prod name="interscan_webmanager" vendor="trend_micro">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0679" seq="2001-0679" published="1999-11-08" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=94204166130782&amp;w=2">19991108 Patch for VirusWall 3.23.</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94208143007829&amp;w=2">19991108 Patch for VirusWall 3.23.</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=94216491202063&amp;w=2">19991109 InterScan VirusWall 3.23/3.3 Buffer Overflow</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9911&amp;L=NTBUGTRAQ&amp;P=R2331" adv="1">19991108 Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3465">viruswall-helo-bo(3465)</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.3"/>
        <vers num="3.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0680" seq="2001-0680" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ftpd in QPC QVT/Net 4.0 and AVT/Term 5.0 allows a remote attacker to traverse directories on the web server via a "dot dot" attack in a LIST (ls) command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/216555">20010925 Vulnerabilities in QVT/Term</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176712" adv="1">20010413 QPC FTPd Directory Traversal and BoF Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2618">2618</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6375">qpc-ftpd-directory-traversal(6375)</ref>
    </refs>
    <vuln_soft>
      <prod name="avt_term" vendor="qpc_software">
        <vers num="5.0"/>
      </prod>
      <prod name="qvt_net" vendor="qpc_software">
        <vers num="4.0"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0681" seq="2001-0681" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176712" adv="1">20010413 QPC FTPd Directory Traversal and BoF Vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6376">qpc-ftpd-bo(6376)</ref>
    </refs>
    <vuln_soft>
      <prod name="qvt_net" vendor="qpc_software">
        <vers num="5.0"/>
      </prod>
      <prod name="qvt_term" vendor="qpc_software">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0682" seq="2001-0682" published="2001-08-29" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=97818917222992&amp;w=2">20001230 [DiamondCS Advisory] ZoneAlarm and ZoneAlarm Pro can be blocked from loading by setting a Mutex in memory</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5821">zonealarm-mutex-dos(5821)</ref>
    </refs>
    <vuln_soft>
      <prod name="zonealarm" vendor="zonelabs">
        <vers num="7.0.302.000" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0683" seq="2001-0683" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/165516" adv="1" patch="1">20010226 def-2001-08: Netscape Collabra DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6158">netscape-collabra-kernel-dos(6158)</ref>
    </refs>
    <vuln_soft>
      <prod name="collabra_server" vendor="netscape">
        <vers num="3.5.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0684" seq="2001-0684" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/165516" adv="1" patch="1">20010226 def-2001-08: Netscape Collabra DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6159">netscape-collabra-cpu-dos(6159)</ref>
    </refs>
    <vuln_soft>
      <prod name="collabra_server" vendor="netscape">
        <vers num="3.5.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0685" seq="2001-0685" published="2001-09-20" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on the fcrontab temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://fcron.free.fr/CHANGES.html">http://fcron.free.fr/CHANGES.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98339581702282&amp;w=2">20010228 fcron 0.9.5 is vulnerable to a symlink attack</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2835" adv="1" patch="1">2835</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7127">fcron-tmpfile-symlink(7127)</ref>
    </refs>
    <vuln_soft>
      <prod name="fcron" vendor="thibault_godouet">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0686" seq="2001-0686" published="2001-09-20" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0000.html" adv="1" patch="1">20010604 $HOME buffer overflow in SunOS 5.8 x86</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2819" adv="1">2819</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6638">solaris-mail-home-bo(6638)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="5.8" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0687" seq="2001-0687" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/190032" adv="1">20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2853" adv="1">2853</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6674">broker-ftp-cd-directory-traversal(6674)</ref>
    </refs>
    <vuln_soft>
      <prod name="broker_ftp_server" vendor="transsoft">
        <vers num="4.0"/>
        <vers num="4.7.5.0"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.9.5.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0688" seq="2001-0688" published="2001-09-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/190032" adv="1">20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2851" adv="1">2851</ref>
    </refs>
    <vuln_soft>
      <prod name="broker_ftp_server" vendor="transsoft">
        <vers num="3.0_build_1"/>
        <vers num="4.0"/>
        <vers num="4.7.5.0"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.7"/>
        <vers num="5.9.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0689" seq="2001-0689" published="2001-09-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0065.html" adv="1">20010607 [SNS Advisory No.29] Trend Micro Virus Control System(VCS)</ref>
    </refs>
    <vuln_soft>
      <prod name="virus_control_system" vendor="trend_micro">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0690" seq="2001-0690" published="2001-09-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format strings in SMTP mail headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0041.html" adv="1">20010606 lil' exim format bug</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000402">CLA-2001:402</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-058" adv="1" patch="1">DSA-058</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-078.html" adv="1" patch="1">RHSA-2001:078</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2828">2828</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6671">exim-syntax-format-string(6671)</ref>
    </refs>
    <vuln_soft>
      <prod name="exim" vendor="university_of_cambridge">
        <vers num="3.22" prev="1"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num=""/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="4.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0691" seq="2001-0691" published="2001-09-20" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6269.php">imap-ipop2d-ipop3d-bo(6269)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-094.html">RHSA-2001:094</ref>
      <ref source="MANDRAKE" url="http://www.securityfocus.com/advisories/3352" adv="1" patch="1">MDKSA-2001:054</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2856" adv="1" patch="1">2856</ref>
    </refs>
    <vuln_soft>
      <prod name="imapd" vendor="university_of_washington">
        <vers num="2000"/>
        <vers num="2000c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0692" seq="2001-0692" published="2001-09-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email attachment whose boundary name ends in two dashes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99379787421319&amp;w=2">20010628 RE: WatchGuard SMTP Proxy issue</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/189783" adv="1">20010608 WatchGuard SMTP Proxy issue</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2855" adv="1" patch="1">2855</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6682">firebox-smtp-bypass-filter(6682)</ref>
    </refs>
    <vuln_soft>
      <prod name="firebox_2500" vendor="watchguard">
        <vers num="4.5"/>
        <vers num="4.6"/>
      </prod>
      <prod name="firebox_4500" vendor="watchguard">
        <vers num="4.5"/>
        <vers num="4.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0693" seq="2001-0693" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99166905208903&amp;w=2">20010603 Webtrends HTTP Server %20 bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2812" adv="1">2812</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6639">webtrends-unicode-reveal-source(6639)</ref>
    </refs>
    <vuln_soft>
      <prod name="webtrends_enterprise_reporting_server" vendor="webtrends">
        <vers num="3.1c"/>
      </prod>
      <prod name="webtrends_enterprise_reporting_server_nt" vendor="webtrends">
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0694" seq="2001-0694" published="2001-09-20" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0454.html" adv="1" patch="1">20010525 WFTPD 32-bit (X86) 3.00 R5 Directory Traversal / Buffer Overflow / DoS</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="3.00_r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0695" seq="2001-0695" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/182054" adv="1" patch="1">20010503 Potential DOS Vulnerability in WFTPD</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6496">wftpd-cd-dos(6496)</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="3.00_r5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0696" seq="2001-0696" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://netwinsite.com/surgeftp/manual/updates.htm">http://netwinsite.com/surgeftp/manual/updates.htm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/191916" adv="1" patch="1">20010619 SurgeFTP vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2891" adv="1" patch="1">2891</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6712">surgeftp-concon-dos(6712)</ref>
    </refs>
    <vuln_soft>
      <prod name="surgeftp" vendor="netwin">
        <vers num="1.0b"/>
        <vers num="2.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0697" seq="2001-0697" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://netwinsite.com/surgeftp/manual/updates.htm">http://netwinsite.com/surgeftp/manual/updates.htm</ref>
      <ref source="WIN2KSEC" url="http://www.secadministrator.com/Articles/Index.cfm?ArticleID=20200" adv="1" patch="1">20010301 SurgeFTP 1.0b Denial of Service</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/165816" adv="1" patch="1">20010228 SurgeFTP Denial of Service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2442">2442</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6168">surgeftp-listing-dos(6168)</ref>
    </refs>
    <vuln_soft>
      <prod name="surgeftp" vendor="netwin">
        <vers num="1.1h" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0698" seq="2001-0698" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.netwinsite.com/surgeftp/manual/updates.htm">http://www.netwinsite.com/surgeftp/manual/updates.htm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/191916" adv="1" patch="1">20010619 SurgeFTP vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2892" adv="1" patch="1">2892</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6711">surgeftp-nlist-directory-traversal(6711)</ref>
    </refs>
    <vuln_soft>
      <prod name="surgeftp" vendor="netwin">
        <vers num="1.0b"/>
        <vers num="2.0a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0699" seq="2001-0699" published="2001-09-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cb_reset in the System Service Processor (SSP) package of SunOS 5.8 allows a local user to execute arbitrary code via a long argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192299" adv="1">20010620 Solaris /opt/SUNWssp/bin/cb_reset Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2893" adv="1">2893</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6726">sun-cbreset-bo(6726)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0700" seq="2001-0700" published="2001-09-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000434">CLA-2001:434</ref>
      <ref source="CONFIRM" url="http://mi.med.tohoku.ac.jp/~satodai/w3m-dev-en/200106.month/537.html" adv="1" patch="1">http://mi.med.tohoku.ac.jp/~satodai/w3m-dev-en/200106.month/537.html</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-064">DSA-064</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-081">DSA-081</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192371">20010621 [SNS Advisory No.32] w3m malformed MIME header Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2895" adv="1" patch="1">2895</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6725">w3m-mime-header-bo(6725)</ref>
    </refs>
    <vuln_soft>
      <prod name="w3m" vendor="w3m">
        <vers num="0.1.3"/>
        <vers num="0.1.4"/>
        <vers num="0.1.6"/>
        <vers num="0.1.7"/>
        <vers num="0.1.8"/>
        <vers num="0.1.9"/>
        <vers num="0.1.10"/>
        <vers num="0.2"/>
        <vers num="0.2.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0701" seq="2001-0701" published="2001-09-20" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ptexec in the Sun Validation Test Suite 4.3 and earlier allows a local user to gain privileges via a long -o argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192667" adv="1">20010621 Solaris /opt/SUNWvts/bin/ptexec Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2898" adv="1" patch="1">2898</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6736">sunvts-ptexec-bo(6736)</ref>
    </refs>
    <vuln_soft>
      <prod name="sunvts" vendor="sun">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0702" seq="2001-0702" published="2001-09-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html">20010704 CesarFTPd, Cerberus FTPd</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192655" adv="1">20010621 Cerberus FTP Server 1.x Remote DoS attack Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2901" adv="1">2901</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6728">cerberus-ftp-bo(6728)</ref>
    </refs>
    <vuln_soft>
      <prod name="ceberus_ftp_server" vendor="grant_averett">
        <vers num="1.0"/>
        <vers num="1.01"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.5"/>
        <vers num="1.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0703" seq="2001-0703" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192651" adv="1">20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2905" adv="1" patch="1">2905</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6739">arcadia-tradecli-dos(6739)</ref>
    </refs>
    <vuln_soft>
      <prod name="arcadia_internet_store" vendor="arcadia">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0704" seq="2001-0704" published="2001-09-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192651" adv="1">20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2904" adv="1" patch="1">2904</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6738">arcadia-tradecli-reveal-path(6738)</ref>
    </refs>
    <vuln_soft>
      <prod name="arcadia_internet_store" vendor="arcadia">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0705" seq="2001-0705" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192651" adv="1">20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2902" adv="1" patch="1">2902</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6737">arcadia-tradecli-directory-traversal(6737)</ref>
    </refs>
    <vuln_soft>
      <prod name="arcadia_internet_store" vendor="arcadia">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0706" seq="2001-0706" published="2001-09-20" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/190932" adv="1">20010612 Rumpus FTP DoS vol. 2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2864" adv="1" patch="1">2864</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6699">rumpus-ftp-directory-dos(6699)</ref>
    </refs>
    <vuln_soft>
      <prod name="rumpus_ftp_server" vendor="maxum_development_corporation">
        <vers num="1.3.2"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="2.0.3dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0707" seq="2001-0707" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/183911" adv="1">20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6523">denicomp-rshd-dos(6523)</ref>
    </refs>
    <vuln_soft>
      <prod name="rshd" vendor="denicomp">
        <vers num="2.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0708" seq="2001-0708" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/183911" adv="1">20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6524">denicomp-rexecd-dos(6524)</ref>
    </refs>
    <vuln_soft>
      <prod name="rexecd" vendor="denicomp">
        <vers num="1.05" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0709" seq="2001-0709" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192802" adv="1" patch="1">20010622 [VIGILANTE-2001001] ASP source code retrieved with Unicode extens ion</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2909" adv="1" patch="1">2909</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6742">iis-unicode-asp-disclosure(6742)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0710" seq="2001-0710" published="2001-09-20" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:52.fragment.asc" adv="1" patch="1">FreeBSD-SA-01:52</ref>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-006.txt.asc" adv="1" patch="1">NetBSD-SA2001-006</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2799" adv="1" patch="1">2799</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6636">bsd-ip-fragments-dos(6636)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.3" prev="1"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0711" seq="2001-0711" published="2001-08-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/ios-snmp-ilmi-vuln-pub.shtml" adv="1" patch="1">20010207 Cisco IOS Software SNMP Read-Write ILMI Community String Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6169">cisco-ios-modify-snmp(6169)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11"/>
        <vers num="12.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0712" seq="2001-0712" published="2001-10-30" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200109" adv="1" patch="1">20010727 TXT or HTML? -- IE NEW BUG</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200291" adv="1" patch="1">20010729 Re: TXT or HTML? -- IE NEW BUG</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3116" adv="1">3116</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0713" seq="2001-0713" published="2001-10-30" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_sm812.html" adv="1">20011001 Multiple Local Sendmail Vulnerabilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7192.php">sendmail-setregid-gain-privileges(7192)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3377">3377</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.12.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0714" seq="2001-0714" published="2001-10-30" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011101-01-I">20011101-01-I</ref>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_sm812.html" adv="1" patch="1">20011001 Multiple Local Sendmail Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.12.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0715" seq="2001-0715" published="2001-10-30" modified="2011-03-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011101-01-I">20011101-01-I</ref>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_sm812.html" adv="1" patch="1">20011001 Multiple Local Sendmail Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.12.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0716" seq="2001-0716" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3440">3440</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise99.php" adv="1" patch="1">20011016 Citrix MetaFrame Remote Denial of Service Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7068">metaframe-multiple-sessions-dos(7068)</ref>
    </refs>
    <vuln_soft>
      <prod name="metaframe" vendor="citrix">
        <vers num="1.8" edition="sp3"/>
        <vers num="xp_server"/>
        <vers num="xp_server_service_pack_1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0717" seq="2001-0717" published="2001-10-30" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.28/CSSA-2001-SCO.28.txt">CSSA-2001-SCO.28</ref>
      <ref source="COMPAQ" url="http://ftp.support.compaq.com/patches/.new/html/SSRT0767U.shtml">SSRT0767U</ref>
      <ref source="HP" url="http://online.securityfocus.com/advisories/3584">HPSBUX0110-168</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1002479">1002479</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/212">00212</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-27.html">CA-2001-27</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-002.shtml">M-002</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3382">3382</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise98.php" adv="1" patch="1">20011002 Multi-Vendor Format String Vulnerability in ToolTalk Service</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7069">tooltalk-ttdbserverd-format-string(7069)</ref>
    </refs>
    <vuln_soft>
      <prod name="tooltalk_database_server" vendor="tooltalk">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0718" seq="2001-0718" published="2001-10-30" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/218802">20011005 Symantec Security Response SecBul-10042001, Revision1, Malformed Microsoft Excel or PowerPoint documents bypass Microsoft macro security features</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-28.html" adv="1" patch="1">CA-2001-28</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/287067">VU#287067</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3402">3402</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-050">MS01-050</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7223">ms-malformed-document-macro(7223)</ref>
    </refs>
    <vuln_soft>
      <prod name="excel" vendor="microsoft">
        <vers num="2002" prev="1"/>
      </prod>
      <prod name="powerpoint" vendor="microsoft">
        <vers num="2002" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0719" seq="2001-0719" published="2001-12-06" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/202470">20010807 MS Windows Media Player ASF Marker Buffer Overflow</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6962.php">mediaplayer-asf-marker-bo(6962)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3156">3156</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-056">MS01-056</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A287">oval:org.mitre.oval:def:287</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_media_player" vendor="microsoft">
        <vers num="6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0720" seq="2001-0720" published="2001-12-06" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to be downloaded, which causes the files to be executed if automatic decoding is enabled.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-013.shtml">M-013</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3471">3471</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-053">MS01-053</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7336">ie-mac-downloaded-file-execution(7336)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0721" seq="2001-0721" published="2001-12-06" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100467787323377&amp;w=2">20011101 Three Windows XP UPNP DOS attacks</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100528449024158&amp;w=2">20011109 Important Information Regarding MS01-054 and WindowsME</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-054">MS01-054</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0722" seq="2001-0722" published="2001-12-06" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100527618108521&amp;w=2">20011108 Microsoft IE cookies readable via about: URLS</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-016.shtml">M-016</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/221612" adv="1" patch="1">20011019 Minor IE vulnerability: about: URLs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3513">3513</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-055">MS01-055</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7486">ie-about-cookie-information(7486)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0723" seq="2001-0723" published="2001-11-14" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3546" adv="1" patch="1">3546</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-055">MS01-055</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0724" seq="2001-0724" published="2001-11-14" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 allows remote attackers to bypass security restrictions via malformed URLs that contain dotless IP addresses, which causes Internet Explorer to process the page in the Intranet Zone, which may have fewer security restrictions, aka the "Zone Spoofing Vulnerability variant" of CVE-2001-0664.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-055">MS01-055</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8471">ie-incorrect-security-zone-variant(8471)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0726" seq="2001-0726" published="2001-12-06" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3650">3650</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-057">MS01-057</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7663">exchange-owa-embedded-script-execution(7663)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0727" seq="2001-0727" published="2001-12-14" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100835204509262&amp;w=2">20011214 MSIE may download and run progams automatically</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100861273114437&amp;w=2">20011216 Re: MSIE may download and run progams automatically - NOT SO FAST</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-36.html" adv="1" patch="1">CA-2001-36</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-027.shtml">M-027</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/443699">VU#443699</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3578">3578</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-058">MS01-058</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7703">ie-file-download-execution(7703)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A921">oval:org.mitre.oval:def:921</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0728" seq="2001-0728" published="2001-10-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Compaq Management Agents before 5.2, included in Compaq Web-enabled Management Software, allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="COMPAQ" url="http://www.compaq.com/products/servers/management/mgtsw-advisory2.html" adv="1" patch="1">SSRT0758</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/275979">VU#275979</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3376">3376</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7189">compaq-wbm-bo(7189)</ref>
    </refs>
    <vuln_soft>
      <prod name="management_agents" vendor="compaq">
        <vers num="5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0729" seq="2001-0729" published="2001-10-30" modified="2012-10-22" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1017522">1017522</ref>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/01-09-28#security">http://www.apacheweek.com/issues/01-09-28#security</ref>
      <ref source="CONFIRM" url="http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html">http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/22083">22083</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0730" seq="2001-0730" published="2001-10-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000430">CLA-2001:430</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077">MDKSA-2001:077</ref>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/01-09-28#security">http://www.apacheweek.com/issues/01-09-28#security</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1649.html">ESA-20011019-01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-126.html">RHSA-2001:126</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-164.html">RHSA-2001:164</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7419">apache-log-file-overwrite(7419)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0731" seq="2001-0731" published="2001-10-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P">20020301-01-P</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077">MDKSA-2001:077</ref>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/01-10-05#security" patch="1">http://www.apacheweek.com/issues/01-10-05#security</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-126.html">RHSA-2001:126</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-164.html">RHSA-2001:164</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/20010709214744.A28765@brasscannon.net">20010709 How Google indexed a file with no external link</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3009">3009</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8275">apache-multiviews-directory-listing(8275)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0733" seq="2001-0733" published="2001-10-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The #sinclude directive in Embedded Perl (ePerl) 2.2.14 and earlier allows a remote attacker to execute arbitrary code by modifying the 'sinclude' file to point to another file that contains a #include directive that references a file that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192711" adv="1" patch="1">20010621 bugtraq submission</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2912" adv="1">2912</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6743">eperl-embedded-code-execution(6743)</ref>
    </refs>
    <vuln_soft>
      <prod name="eperl" vendor="ralf_s._engelschall">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0734" seq="2001-0734" published="2001-10-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-008.txt.asc" adv="1" patch="1">NetBSD-SA2001-008</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2810" adv="1" patch="1">2810</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6637">bsd-sh3-sigreturn-privileges(6637)</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4.1" edition=":sh3"/>
        <vers num="1.5" edition=":sh3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0735" seq="2001-0735" published="2001-10-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-066" adv="1" patch="1">DSA-066</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/01071120191900.00788@localhost.localdomain">20010711 Another exploit for cfingerd &lt;= 1.4.3-8</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192844" adv="1" patch="1">20010621 cfingerd local vulnerability (possibly root)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2914" adv="1" patch="1">2914</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6744">cfingerd-util-bo(6744)</ref>
    </refs>
    <vuln_soft>
      <prod name="cfingerd" vendor="infodrom">
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0736" seq="2001-0736" published="2001-10-18" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98749102621604&amp;w=2">20010416 Immunix OS Security update for pine</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99106787825229&amp;w=2">20010527 [ESA-20010509-01]  pine temporary file handling vulnerabilities</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-047.php3?dis=8.0" adv="1" patch="1">MDKSA-2001:047</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-042.html" adv="1" patch="1">RHSA-2001:042</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6367">pine-tmp-file-symlink(6367)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="pine" vendor="university_of_washington">
        <vers num="4.33" prev="1"/>
      </prod>
      <prod name="secure_linux" vendor="engardelinux">
        <vers num="1.0.1"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="8.0"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="5.2"/>
        <vers num="6.2"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0737" seq="2001-0737" published="2001-10-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/185003" adv="1">20010516 logitech wireless devices: man-in-the-middle attack</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/3B0A36C8.E9D8610@daten-treuhand.de" adv="1">20010522 Logitech vulnerability (DoS, man-in-the-middle-attack) - Resend</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2738" adv="1">2738</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6562">logitech-wireless-unauthorized-access(6562)</ref>
    </refs>
    <vuln_soft>
      <prod name="cordless_freedom" vendor="logitech">
        <vers num=""/>
      </prod>
      <prod name="cordless_freedom_navigator" vendor="logitech">
        <vers num=""/>
      </prod>
      <prod name="cordless_freedom_pro" vendor="logitech">
        <vers num=""/>
      </prod>
      <prod name="cordless_itouch_keyboard" vendor="logitech">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0738" seq="2001-0738" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-026-01">IMNX-2001-70-026-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99258618906506&amp;w=2">20010614 sysklogd update -- Immunix OS 6.2, 7.0-beta, 7.0</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/249579" adv="1" patch="1">VU#249579</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7098">klogd-null-byte-dos(7098)</ref>
    </refs>
    <vuln_soft>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="1.3"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0739" seq="2001-0739" published="2001-10-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Guardian Digital WebTool in EnGarde Secure Linux 1.0.1 allows restarted services to inherit some environmental variables, which could allow local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1404.html" adv="1" patch="1">ESA-20010529-02</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-126.html">RHSA-2001:126</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7404">linux-webtool-inherit-privileges(7404)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_linux" vendor="engardelinux">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0740" seq="2001-0740" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service via a long string containing a large number of "%s" strings, possibly triggering a format string vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0115.html" adv="1">20010515 3COM OfficeConnect DSL router vulneratibilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100119572524232&amp;w=2">20010921 3Com OfficeConnect 812/840  Router DoS exploit code</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100137290421828&amp;w=2">20010924 Regarding: 3Com OfficeConnect 812/840 Router DoS exploit code</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2721" adv="1" patch="1">2721</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6573">3com-officeconnect-http-dos(6573)</ref>
    </refs>
    <vuln_soft>
      <prod name="3c840-us" vendor="3com">
        <vers num="1.1.9" prev="1"/>
      </prod>
      <prod name="3cp4144" vendor="3com">
        <vers num="1.1.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0741" seq="2001-0741" published="2001-10-18" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0035.html" adv="1">20010503 Cisco HSRP Weakness/DoS</ref>
      <ref source="MISC" url="http://www.cisco.com/networkers/nw00/pres/2402.pdf">http://www.cisco.com/networkers/nw00/pres/2402.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2684" adv="1">2684</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6497">cisco-hsrp-dos(6497)</ref>
    </refs>
    <vuln_soft>
      <prod name="hsrp" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0742" seq="2001-0742" published="2001-10-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5UP0B204AY.html" adv="1">http://www.securiteam.com/windowsntfocus/5UP0B204AY.html</ref>
    </refs>
    <vuln_soft>
      <prod name="cmail" vendor="computalynx">
        <vers num="2.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0743" seq="2001-0743" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0326.html" adv="1">20010602 O'Reilly WebBoard 4.10.30 JavaScript code execution problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2814" adv="1">2814</ref>
    </refs>
    <vuln_soft>
      <prod name="webboard" vendor="oreilly">
        <vers num="4.10.30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0744" seq="2001-0744" published="2001-10-18" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-025.0.txt">CSSA-2001-025.0</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0303.html" adv="1" patch="1">20010531 Imp-2.2.4 temporary files</ref>
      <ref source="CONFIRM" url="http://www.horde.org/imp/2.2/news.php" patch="1">http://www.horde.org/imp/2.2/news.php</ref>
    </refs>
    <vuln_soft>
      <prod name="imp" vendor="horde">
        <vers num="2.0"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0745" seq="2001-0745" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape 4.7x allows remote attackers to obtain sensitive information such as the user's login, mailbox location and installation path via Javascript that accesses the mailbox: URL in the document.referrer property.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0014.html" adv="1">20010605 SECURITY.NNOV: Netscape 4.7x Messanger user information retrival</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7417">netscape-user-info-retrieval(7417)</ref>
    </refs>
    <vuln_soft>
      <prod name="messanger" vendor="netscape">
        <vers num="4.7x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0746" seq="2001-0746" published="2001-10-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0132.html" adv="1" patch="1">20010515 iPlanet - Netscape Enterprise Web Publisher Buffer Overflow</ref>
      <ref source="CONFIRM" url="http://iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html" adv="1" patch="1">http://iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2732" adv="1" patch="1">2732</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6554">netscape-enterprise-uri-bo(6554)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="iplanet">
        <vers num="4.1_sp3"/>
        <vers num="4.1_sp4"/>
        <vers num="4.1_sp5"/>
        <vers num="4.1_sp6"/>
        <vers num="4.1_sp7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0747" seq="2001-0747" published="2001-10-18" modified="2017-08-16" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long method name in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0203.html" adv="1" patch="1">20010518 Netscape Enterprise Server 4 Method and URI overflow</ref>
      <ref source="CONFIRM" url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html" adv="1" patch="1">http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="iplanet">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0748" seq="2001-0748" published="2001-10-18" modified="2017-07-11" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/acmeweb-acsunix-dirtravers-vuln-pub.shtml" adv="1">20020702 Cisco Secure ACS Unix Acme.server Information Disclosure Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6634.php">acme-serve-directory-traversal(6634)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/188141" adv="1">20010531 Acme.Server v1.7 of 13nov96 Directory Browsing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2809" adv="1">2809</ref>
    </refs>
    <vuln_soft>
      <prod name="acme_server" vendor="acme_labs">
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0749" seq="2001-0749" published="2001-05-24" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186418" adv="1" patch="1">20010524 IPC@Chip Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2775" adv="1">2775</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8922">ipcchip-web-root-system(8922)</ref>
    </refs>
    <vuln_soft>
      <prod name="ipc_at_chip_embedded-webserver" vendor="beck_ipc_gmbh">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0750" seq="2001-0750" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/ios-tcp-scanner-reload-pub.shtml" adv="1" patch="1">20010524 IOS Reload after Scanning Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2804">2804</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6589">cisco-ios-tcp-dos(6589)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.1(2)t"/>
        <vers num="12.1(3)t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0751" seq="2001-0751" published="2001-10-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco switches and routers running CBOS 2.3.8 and earlier use predictable TCP Initial Sequence Numbers (ISN), which allows remote attackers to spoof or hijack TCP connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html" adv="1" patch="1">20010522 More Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/139">tcp-seq-predict(139)</ref>
    </refs>
    <vuln_soft>
      <prod name="cbos" vendor="cisco">
        <vers num="2.3.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0752" seq="2001-0752" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via an ICMP ECHO REQUEST (ping) with the IP Record Route option set.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html" adv="1" patch="1">20010522 More Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7298">cisco-cbos-record-dos(7298)</ref>
    </refs>
    <vuln_soft>
      <prod name="cbos" vendor="cisco">
        <vers num="2.3.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0753" seq="2001-0753" published="2001-10-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html" adv="1" patch="1">20010522 More Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/44544">cisco-cbos-execenable-info-disclosure(44544)</ref>
    </refs>
    <vuln_soft>
      <prod name="cbos" vendor="cisco">
        <vers num="2.3.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0754" seq="2001-0754" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html">20010522 More Multiple Vulnerabilities in CBOS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7299">cisco-cbos-multiple-echo(7299)</ref>
    </refs>
    <vuln_soft>
      <prod name="cbos" vendor="cisco">
        <vers num="2.3.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0755" seq="2001-0755" published="2001-10-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0188.html" adv="1">20010518 Tamersahin.net Security Announcement: Debian 2.2 is 2.2r3 Ftpd Daemon Buffer Owerflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0756" seq="2001-0756" published="2001-10-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CatalogMgr.pl in VirtualCatalog (incorrectly claimed to be in VirtualCart) allows remote attackers to execute arbitrary code via the template parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0067.html" adv="1" patch="1">20010607 cgisecurity.com Advisory #5</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99237435902211&amp;w=2">20010611 re: Advisory #5 Corrections.</ref>
    </refs>
    <vuln_soft>
      <prod name="virtualcatalog" vendor="virtualcart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0757" seq="2001-0757" published="2001-10-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-097.shtml">L-097</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/6400-nrp2-telnet-vuln-pub.shtml" adv="1" patch="1">20010614 Cisco 6400 NRP2 Telnet Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/516659">VU#516659</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2874" adv="1" patch="1">2874</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6691">cisco-nrp2-telnet-access(6691)</ref>
    </refs>
    <vuln_soft>
      <prod name="6400_nrp_2" vendor="cisco">
        <vers num="12.1dc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0758" seq="2001-0758" published="2001-10-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..."  command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5SP011P4KC.html" adv="1">http://www.securiteam.com/windowsntfocus/5SP011P4KC.html</ref>
    </refs>
    <vuln_soft>
      <prod name="shambala_server" vendor="evolvable_corporation">
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0759" seq="2001-0759" published="2001-10-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file or directory with a long pathname, which is processed during an unmount.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/191111" adv="1" patch="1">20010614 Buffer overflow in BestCrypt for Linux</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2875" adv="1" patch="1">2875</ref>
    </refs>
    <vuln_soft>
      <prod name="bestcrypt" vendor="jetico">
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0760" seq="2001-0760" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194449" adv="1">20010630 Nfuse reveals full path</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194522" adv="1">20010702 Re: Nfuse reveals full path</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2956" adv="1">2956</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6786">citrix-nfuse-path-disclosure(6786)</ref>
    </refs>
    <vuln_soft>
      <prod name="nfuse" vendor="citrix">
        <vers num="1.51"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0761" seq="2001-0761" published="2001-10-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in HttpSave.dll in Trend Micro InterScan WebManager 1.2 allows remote attackers to execute arbitrary code via a long value to a certain parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194463" adv="1">20010702 [SNS Advisory No.36] TrendMicro InterScan WebManager Version 1.2 HttpSave.dll Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2959" adv="1">2959</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_webmanager" vendor="trend_micro">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0762" seq="2001-0762" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0057.html" adv="1">20010602 su-wrapper 1.1.1 Local root exploit.</ref>
    </refs>
    <vuln_soft>
      <prod name="su-wrapper" vendor="su-wrapper">
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0763" seq="2001-0763" published="2001-10-18" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is not properly handled by the svc_logprint function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0064.html" adv="1">20010608 potential buffer overflow in xinetd-2.1.8.9pre11-1</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000404">CLA-2001:404</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-024-01">IMNX-2001-70-024-01</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-104.shtml">L-104</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-063" adv="1" patch="1">DSA-063</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1469.html">ESA-20010621-01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-075.html">RHSA-2001:075</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2840">2840</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6670">xinetd-identd-bo(6670)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1.8.8.p3-1.1" prev="1"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0764" seq="2001-0764" published="2001-10-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0579.html">20010609 suid scotty / ntping overflow</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0627.html">20010615 Re: suid scotty (ntping) overflow (fwd)</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_023_scotty_txt.html">SuSE-SA:2001:023</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192664" adv="1" patch="1">20010621 suid scotty (ntping) overflow (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2911" adv="1" patch="1">2911</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6735">scotty-ntping-bo(6735)</ref>
    </refs>
    <vuln_soft>
      <prod name="scotty" vendor="juergen_schoenwaelder">
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0765" seq="2001-0765" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0025.html" adv="1">20010702 BisonFTP Server V4R1 *.bdl upload Directory Traversal</ref>
      <ref source="CONFIRM" url="http://www.bisonftp.com/ServRev.htm" adv="1">http://www.bisonftp.com/ServRev.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2963" adv="1" patch="1">2963</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6782">bisonftp-bdl-directory-traversal(6782)</ref>
    </refs>
    <vuln_soft>
      <prod name="bison_ftp_server" vendor="bisonware">
        <vers num="v4r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0766" seq="2001-0766" published="2001-10-18" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0090.html" adv="1" patch="1">20010610 Mac OS X - Apache &amp; Case Insensitive Filesystems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2852" adv="1" patch="1">2852</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0767" seq="2001-0767" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0250.html" adv="1">20010526 GuildFTPD v0.97 Directory Traversal / Weak password encryption</ref>
      <ref source="MISC" url="http://www.nitrolic.com/" adv="1" patch="1">http://www.nitrolic.com/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2789" adv="1">2789</ref>
    </refs>
    <vuln_soft>
      <prod name="guildftpd" vendor="steve_poulsen">
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0768" seq="2001-0768" published="2001-10-18" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0250.html" adv="1">20010526 GuildFTPD v0.97 Directory Traversal / Weak password encryption</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2792" adv="1">2792</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6611">guildftpd-usr-plaintext-passwords(6611)</ref>
    </refs>
    <vuln_soft>
      <prod name="guildftpd" vendor="steve_poulsen">
        <vers num="0.9.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0769" seq="2001-0769" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0254.html" adv="1">20010527 def-2001-27: GuildFTPD Buffer Overflow and Memory Leak DoS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6613">guildftpd-null-memory-leak(6613)</ref>
    </refs>
    <vuln_soft>
      <prod name="guildftpd" vendor="steve_poulsen">
        <vers num="0.97"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0770" seq="2001-0770" published="2001-10-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0254.html" adv="1">20010527 def-2001-27: GuildFTPD Buffer Overflow and Memory Leak DoS</ref>
      <ref source="CONFIRM" url="http://www.nitrolic.com/help/history.htm">http://www.nitrolic.com/help/history.htm</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6612">guildftpd-site-bo(6612)</ref>
    </refs>
    <vuln_soft>
      <prod name="guildftpd" vendor="steve_poulsen">
        <vers num="0.97"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0771" seq="2001-0771" published="2001-10-18" modified="2018-11-29" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Spytech SpyAnywhere 1.50 allows remote attackers to gain administrator access via a single character in the "loginpass" field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186006" adv="1">20010521 SpyAnywhere Authentication Bypassing Vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2755" adv="1">2755</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6578">spyanywhere-weak-authentication(6578)</ref>
    </refs>
    <vuln_soft>
      <prod name="spyanywhere" vendor="spytech-web">
        <vers num="1.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0772" seq="2001-0772" published="2001-10-18" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q2/0044.html" adv="1" patch="1">HPSBUX0105-151</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6585">hpux-cde-bo(6585)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6022">oval:org.mitre.oval:def:6022</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.10"/>
        <vers num="11.11" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0773" seq="2001-0773" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cayman 3220-H DSL Router 1.0 allows remote attacker to cause a denial of service (crash) via a series of SYN or TCP connect requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/312761">VU#312761</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195644" adv="1">20010709 Cayman-DSL Model 3220-H DOS with nmap</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3001" adv="1">3001</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6825">cayman-dsl-portscan-dos(6825)</ref>
    </refs>
    <vuln_soft>
      <prod name="3220-h_dsl_router" vendor="cayman">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0774" seq="2001-0774" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Tripwire 1.3.1, 2.2.1 and 2.3.0 allows local users to overwrite arbitrary files and possible gain privileges via a symbolic link attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/349019">VU#349019</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-064.php3">MDKSA-2001:064</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195617" adv="1" patch="1">20010709 Tripwire temporary files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3003" adv="1" patch="1">3003</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6820">tripwire-tmpfile-symlink(6820)</ref>
    </refs>
    <vuln_soft>
      <prod name="tripwire" vendor="tripwire">
        <vers num="1.3.1"/>
        <vers num="2.2.1"/>
        <vers num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0775" seq="2001-0775" published="2001-10-18" modified="2016-05-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-069">DSA-069</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-695">DSA-695</ref>
      <ref source="GENTOO" url="http://www.gentoo.org/security/en/glsa/glsa-200503-05.xml">GLSA-200503-05</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6821.php">xloadimage-faces-bo(6821)</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_024_xli_txt.html">SA:2001:024</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-088.html">RHSA-2001:088</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195823" adv="1" patch="1">20010710 xloadimage remote exploit - tstot.c</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3006" adv="1" patch="1">3006</ref>
    </refs>
    <vuln_soft>
      <prod name="xli" vendor="xli">
        <vers num="1.16"/>
        <vers num="1.17"/>
      </prod>
      <prod name="xloadimage" vendor="xloadimage">
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0776" seq="2001-0776" published="2001-10-18" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in DynFX MailServer version 2.10 allows remote attackers to conduct a denial of service via a long username to the POP3 service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0278.html" adv="1" patch="1">20010526 DynFX POPd Denial of Service Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2781" adv="1" patch="1">2781</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6615">dynfx-mailserver-pop3-bo(6615)</ref>
    </refs>
    <vuln_soft>
      <prod name="dynfx_mailserver" vendor="dynfx">
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0777" seq="2001-0777" published="2001-10-18" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0248.html" adv="1">20010526 Remote vulnerabilities in OmniHTTPd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2783" adv="1">2783</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6620">omnihttpd-php-request-dos(6620)</ref>
    </refs>
    <vuln_soft>
      <prod name="omnihttpd" vendor="omnicron">
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0778" seq="2001-0778" published="2001-10-18" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0248.html" adv="1">20010525 Remote vulnerabilities in OmniHTTPd</ref>
      <ref source="CONFIRM" url="http://www.omnicron.ca/httpd/docs/release.html">http://www.omnicron.ca/httpd/docs/release.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6621">omnihttpd-reveal-source-code(6621)</ref>
    </refs>
    <vuln_soft>
      <prod name="omnihttpd" vendor="omnicron">
        <vers num="2.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0779" seq="2001-0779" published="2001-10-18" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/209">00209</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-008.shtml">M-008</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/327281">VU#327281</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/187086" adv="1" patch="1">20010528 solaris 2.6, 7 yppasswd vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200110041632.JAA28125@dim.ucsd.edu" adv="1" patch="1">20011004 Patches for Solaris rpc.yppasswdd available</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2763" adv="1" patch="1">2763</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6629">solaris-yppasswd-bo(6629)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A102">oval:org.mitre.oval:def:102</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A56">oval:org.mitre.oval:def:56</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0780" seq="2001-0780" published="2001-10-18" modified="2016-05-25" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/187182" adv="1">20010527 directorypro.cgi , directory traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2793" adv="1">2793</ref>
    </refs>
    <vuln_soft>
      <prod name="directory_pro" vendor="cosmicperl">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0781" seq="2001-0781" published="2001-05-30" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in SpoonFTP 1.0.0.12 allows remote attackers to execute arbitrary code via a long argument to the commands (1) CWD or (2) LIST.</descript>
    </desc>
    <sols>
      <sol source="nvd">SpoonFTP v1.0.0.13 fixes problem.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0296.html" adv="1">20010530 SpoonFTP Buffer Overflow Vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6630">spoonftp-cwd-list-bo(6630)</ref>
    </refs>
    <vuln_soft>
      <prod name="spoonftp" vendor="pi-soft">
        <vers num="1.0.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0782" seq="2001-0782" published="2001-10-18" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0302.html" adv="1">20010622 Symlinks symlinks...this time KTVision</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6741">ktvision-symlink(6741)</ref>
    </refs>
    <vuln_soft>
      <prod name="ktv" vendor="kde">
        <vers num="0.1.1.271" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0783" seq="2001-0783" published="2001-10-18" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0227.html" adv="1" patch="1">20010618 Cisco TFTPD 1.1 Vulerablity</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2886" adv="1">2886</ref>
      <ref source="MISC" url="http://www.sentry-labs.com/files/cisco0201061701.txt">http://www.sentry-labs.com/files/cisco0201061701.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6722">cisco-tftp-directory-traversal(6722)</ref>
    </refs>
    <vuln_soft>
      <prod name="tftp_server" vendor="cisco">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0784" seq="2001-0784" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot)  attack using encoded URL characters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0353.html" adv="1">20010626 Advisory</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-089">DSA-089</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-105.html">RHSA-2001:105</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-063.html">RHSA-2002:063</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2932" adv="1">2932</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6752">icecast-dot-directory-traversal(6752)</ref>
    </refs>
    <vuln_soft>
      <prod name="icecast" vendor="icecast">
        <vers num="1.3.7"/>
        <vers num="1.3.8_beta2"/>
        <vers num="1.310" prev="1" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0785" seq="2001-0785" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal in Webpaging interface in Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0228.html" adv="1">20010618 Multiple Vulnerabilities In AMLServer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2883" adv="1">2883</ref>
    </refs>
    <vuln_soft>
      <prod name="air_messenger_lan_server" vendor="internet_software_solutions">
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0786" seq="2001-0786" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 stores user passwords in plaintext in the pUser.Dat file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0228.html">20010618 Multiple Vulnerabilities In AMLServer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2882" adv="1">2882</ref>
    </refs>
    <vuln_soft>
      <prod name="air_messenger_lan_server" vendor="internet_software_solutions">
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0787" seq="2001-0787" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">LPRng in Red Hat Linux 7.0 and 7.1 does not properly drop memberships in supplemental groups when lowering privileges, which could allow a local user to elevate privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-096.shtml">L-096</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-077.html">RHSA-2001:077</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2865">2865</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6703">lprng-supplementary-groups(6703)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0788" seq="2001-0788" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by viewing the Location header.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0228.html" adv="1">20010618 Multiple Vulnerabilities In AMLServer</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2881" adv="1">2881</ref>
    </refs>
    <vuln_soft>
      <prod name="air_messenger_lan_server" vendor="internet_software_solutions">
        <vers num="3.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0789" seq="2001-0789" published="2001-10-18" modified="2018-11-28" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in avpkeeper in Kaspersky KAV 3.5.135.2 for Sendmail allows remote attackers to cause a denial of service or possibly execute arbitrary code via a malformed mail message.</descript>
      <descript source="nvd">&lt;a href="http://cwe.mitre.org/data/definitions/134.html" rel="nofollow">CWE-134: Use of Externally-Controlled Format String&lt;/a></descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0274.html" adv="1" patch="1">20010621 SECURITY.NNOV: KAV (AVP) for sendmail format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="kaspersky_anti-virus" vendor="kaspersky">
        <vers num="3.5.132.2" edition=":~~~sendmail~~"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0790" seq="2001-0790" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Specter IDS version 4.5 and 5.0 allows a remote attacker to cause a denial of service (CPU exhaustion) via a port scan, which causes the server to consume CPU while preparing alerts.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2001-q2/0071.html" adv="1">20010527</ref>
    </refs>
    <vuln_soft>
      <prod name="specter_ids" vendor="specter">
        <vers num="4.5"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0791" seq="2001-0791" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which do not restrict access.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00006.html" adv="1">20010531 [SNS Advisory No.28]InterScan VirusWall for NT remote configuration</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0792" seq="2001-0792" published="2001-10-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/exploits/5AP0Q2A4AQ.html" adv="1">http://www.securiteam.com/exploits/5AP0Q2A4AQ.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7416">xchat-nickname-format-string(7416)</ref>
    </refs>
    <vuln_soft>
      <prod name="xchat" vendor="xchat">
        <vers num="1.2.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0794" seq="2001-0794" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in A-FTP Anonymous FTP Server allows remote attackers to cause a denial of service via a long USER command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0280.html" adv="1">20010621 A-FTP Anonymous FTP Server Remote DoS attack Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="anonymous_ftp_server" vendor="a-ftp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0795" seq="2001-0795" published="2001-10-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0328.html" adv="1" patch="1">20010625 Perception LiteServe MS-DOS filename vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2926" adv="1" patch="1">2926</ref>
    </refs>
    <vuln_soft>
      <prod name="liteserve" vendor="perception">
        <vers num="1.25"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0796" seq="2001-0796" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SGI IRIX 6.5 through 6.5.12f and possibly earlier versions, and FreeBSD 3.0, allows remote attackers to cause a denial of service via a malformed IGMP multicast packet with a small response delay.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011001-01-P" adv="1" patch="1">20011001-01-P</ref>
      <ref source="CONFIRM" url="http://www.freebsd.org/cgi/query-pr.cgi?pr=8990">http://www.freebsd.org/cgi/query-pr.cgi?pr=8990</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3463">3463</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7332">irix-igmp-dos(7332)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="3.0"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.5"/>
        <vers num="6.5.12f" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0797" seq="2001-0797" published="2001-12-12" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011201-01-I">20011201-01-I</ref>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.40/CSSA-2001-SCO.40.txt">CSSA-2001-SCO.40</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100844757228307&amp;w=2">20011214 Sun Solaris login bug patches out</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/213">00213</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-34.html" adv="1" patch="1">CA-2001-34</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/569272">VU#569272</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246487" adv="1">20011219 Linux distributions and /bin/login overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3681" adv="1" patch="1">3681</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY26221&amp;apar=only">IY26221</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise105.php" adv="1" patch="1">20011212 Buffer Overflow in /bin/login</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7284">telnet-tab-bo(7284)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2025">oval:org.mitre.oval:def:2025</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.00"/>
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.0.4"/>
        <vers num="11.11"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="5.1"/>
      </prod>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.3"/>
      </prod>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":ppc"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0798" seq="2001-0798" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0799" seq="2001-0799" published="2001-12-06" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in lpsched in IRIX 6.5.13f and earlier allow remote attackers to execute arbitrary commands via a long argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011003-02-P" adv="1" patch="1">20011003-02-P</ref>
      <ref source="MISC" url="http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2" adv="1">http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7641">irix-lpsched-bo(7641)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.13f" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0800" seq="2001-0800" published="2001-12-06" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011003-02-P" adv="1" patch="1">20011003-02-P</ref>
      <ref source="MISC" url="http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2">http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/27566">27566</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.13f" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0801" seq="2001-0801" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">lpstat in IRIX 6.5.13f and earlier allows local users to gain root privileges by specifying a Trojan Horse nettype shared library.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011003-02-P" adv="1" patch="1">20011003-02-P</ref>
      <ref source="MISC" url="http://www.lsd-pl.net/files/get?IRIX/irx_lpstat2" adv="1">http://www.lsd-pl.net/files/get?IRIX/irx_lpstat2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7639">irix-lpstat-net-type-library(7639)</ref>
    </refs>
    <vuln_soft>
      <prod name="irix" vendor="sgi">
        <vers num="6.5.13f" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0802" seq="2001-0802" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0803" seq="2001-0803" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P">20011107-01-P</ref>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/">CSSA-2001-SCO.30</ref>
      <ref source="COMPAQ" url="http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml">SSRT541</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/214">00214</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-31.html">CA-2001-31</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2002-01.html">CA-2002-01</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/172583" adv="1" patch="1">VU#172583</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3651" adv="1" patch="1">HPSBUX0111-175</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3517" adv="1" patch="1">3517</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise101.php" adv="1">20011112 Multi-Vendor Buffer Overflow Vulnerability in CDE Subprocess Control Service</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7396">cde-dtspcd-bo(7396)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70">oval:org.mitre.oval:def:70</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74">oval:org.mitre.oval:def:74</ref>
    </refs>
    <vuln_soft>
      <prod name="cde_common_desktop_environment" vendor="open_group">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0804" seq="2001-0804" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files via a .. (dot dot) attack on the "next" parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/4.3.2.7.2.20010715184257.00b20100@compumodel.com" adv="1" patch="1">20010715 Interactive Story File Disclosure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3028" adv="1" patch="1">3028</ref>
      <ref source="CONFIRM" url="http://www.valeriemates.com/story_download.html" adv="1" patch="1">http://www.valeriemates.com/story_download.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6843">interactive-story-next-directory-traversal(6843)</ref>
    </refs>
    <vuln_soft>
      <prod name="interactive_story" vendor="valerie_mates">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0805" seq="2001-0805" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the pg parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/20010619150935.A5226@tarantella.com" patch="1">20010619 Re: SCO Tarantella Remote file read via ttawebtop.cgi</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/3B2E37D0.81D9ED9D@snosoft.com">20010618 SCO Tarantella Remote file read via ttawebtop.cgi</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2890" adv="1" patch="1">2890</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6723">tarantella-ttawebtop-read-files(6723)</ref>
    </refs>
    <vuln_soft>
      <prod name="tarantella_enterprise" vendor="tarantella">
        <vers num="3.0"/>
        <vers num="3.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0806" seq="2001-0806" published="2001-12-06" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Apple MacOS X 10.0 and 10.1 allow a local user to read and write to a user's desktop folder via insecure default permissions for the Desktop when it is created in some languages.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99358249631139&amp;w=2">20010626 MacOSX 10.0.X Permissions uncorrectly set</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99436289015729&amp;w=2">20010704 Re: MacOSX 10.0.X Permissions uncorrectly set - I got it</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/219166">20011007 OS X 10.1 and localized desktop folder still vulnerable</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2930" adv="1" patch="1">2930</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6750">macos-desktop-insecure-permissions(6750)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0807" seq="2001-0807" published="2001-12-06" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;mid=189341" adv="1">20010606 security bug Internet Explorer 5</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6688">ie-local-file-disclosure(6688)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0808" seq="2001-0808" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0365.html" adv="1" patch="1">20010627 gnats update</ref>
      <ref source="CONFIRM" url="http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html" adv="1" patch="1">http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6753">gnatsweb-helpfile-execute-commands(6753)</ref>
    </refs>
    <vuln_soft>
      <prod name="gnatsweb" vendor="yngve_svendsen">
        <vers num="2.7_beta"/>
        <vers num="2.8.0"/>
        <vers num="2.8.1"/>
        <vers num="3.95" edition="gnats_4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0809" seq="2001-0809" published="2001-12-06" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q2/0074.html" adv="1" patch="1">HPSBUX0106-155</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5673">oval:org.mitre.oval:def:5673</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0810" seq="2001-0810" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0811" seq="2001-0811" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0812" seq="2001-0812" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0813" seq="2001-0813" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0814" seq="2001-0814" published="2017-05-11" modified="2017-05-11" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2001. Notes: none.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-0815" seq="2001-0815" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.activestate.com/show_bug.cgi?id=18062" adv="1">http://bugs.activestate.com/show_bug.cgi?id=18062</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100583978302585&amp;w=2">20011115 NSFOCUS SA2001-07 : ActivePerl PerlIS.dll Remote Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3526" adv="1" patch="1">3526</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7539">activeperl-perlis-filename-bo(7539)</ref>
    </refs>
    <vuln_soft>
      <prod name="activeperl" vendor="activestate">
        <vers num="5.6.1.629" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0816" seq="2001-0816" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0153.html" adv="1" patch="1">20010918 OpenSSH: sftp &amp; bypassing keypair auth restrictions</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000431">CLSA-2001:431</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01">IMNX-2001-70-034-01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-154.html">RHSA-2001:154</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7634">openssh-sftp-bypass-restrictions(7634)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="2.9.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0817" seq="2001-0817" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q4/0047.html" adv="1" patch="1">HPSBUX0111-176</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-32.html">CA-2001-32</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-021.shtml">M-021</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/638011">VU#638011</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3561">3561</ref>
      <ref source="ISS" url="http://xforce.iss.net/alerts/advise102.php" adv="1" patch="1">20011120 Remote Logic Flaw Vulnerability in HP-UX Line Printer Daemon</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7234">hpux-rlpdaemon-logic-flaw(7234)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0818" seq="2001-0818" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary commands by sending the command a large amount of data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/190933" adv="1" patch="1">20010612 Remote buffer overflow in MDBMS.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2867" adv="1" patch="1">2867</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6700">mdbms-query-display-bo(6700)</ref>
    </refs>
    <vuln_soft>
      <prod name="mdbms" vendor="marty_bochane">
        <vers num="0.96b6"/>
        <vers num="0.99b4"/>
        <vers num="0.99b5"/>
        <vers num="0.99b6"/>
        <vers num="0.99b9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0819" seq="2001-0819" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A buffer overflow in Linux fetchmail before 5.8.6 allows remote attackers to execute arbitrary code via a large 'To:' field in an email header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:43.fetchmail.asc">FreeBSD-SA-01:43</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000403">CLA-2001:403</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-025-01">IMNX-2001-70-025-01</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-022.1.txt">CSSA-2001-022.1</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-060" adv="1" patch="1">DSA-060</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-063.php3?dis=7.1">MDKSA-2001:063</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1451.html" adv="1" patch="1">ESA-20010620-01</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_026_fetchmail_txt.html">SuSE-SA:2001:026</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-103.html">RHSA-2001:103</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2877" adv="1" patch="1">2877</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6704">fetchmail-long-header-bo(6704)</ref>
    </refs>
    <vuln_soft>
      <prod name="fetchmail" vendor="fetchmail">
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.1.0"/>
        <vers num="5.1.4"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.3"/>
        <vers num="5.3.8"/>
        <vers num="5.4.0"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.5.0"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.6.0"/>
        <vers num="5.7.0"/>
        <vers num="5.7.2"/>
        <vers num="5.7.4"/>
        <vers num="5.8"/>
        <vers num="5.8.1"/>
        <vers num="5.8.2"/>
        <vers num="5.8.3"/>
        <vers num="5.8.4"/>
        <vers num="5.8.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0820" seq="2001-0820" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99279182704674&amp;w=2">20010617 Buffer Overflow in GazTek HTTP Daemon v1.4 (ghttpd)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99406263214417&amp;w=2">20010630 Advisory Ghttp 1.4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2879" adv="1">2879</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2965">2965</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6702">gaztek-ghttpd-bo(6702)</ref>
    </refs>
    <vuln_soft>
      <prod name="ghttp" vendor="gaztek">
        <vers num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0821" seq="2001-0821" published="2001-12-06" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0233.html" adv="1">20010618 DCShop vulnerability</ref>
      <ref source="CONFIRM" url="http://www.dcscripts.com/dcforum/dcshop/44.html" adv="1" patch="1">http://www.dcscripts.com/dcforum/dcshop/44.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2889" adv="1" patch="1">2889</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6707">dcshop-cgi-retrieve-information(6707)</ref>
    </refs>
    <vuln_soft>
      <prod name="dcshop" vendor="dcscripts">
        <vers num="1.002_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0822" seq="2001-0822" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">FPF kernel module 1.0 allows a remote attacker to cause a denial of service via fragmented packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99167206319643&amp;w=2">20010602 fpf module and packet fragmentation:local/remote DoS.</ref>
      <ref source="CONFIRM" url="http://www.pkcrew.org/news.php" adv="1">http://www.pkcrew.org/news.php</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2816" adv="1" patch="1">2816</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6659">linux-fpf-kernel-dos(6659)</ref>
    </refs>
    <vuln_soft>
      <prod name="fpf_linux_kernel_module" vendor="packet_knights">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0823" seq="2001-0823" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in the PCP log directory (PCP_LOG_DIR).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010601-01-A" patch="1">20010601-01-A</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0245.html" adv="1" patch="1">20010619 Re: pmpost - another nice symlink follower</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99290754901708&amp;w=2">20010618 pmpost - another nice symlink follower</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2887" adv="1" patch="1">2887</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6724">irix-pcp-pmpost-symlink(6724)</ref>
    </refs>
    <vuln_soft>
      <prod name="performance_co-pilot" vendor="sgi">
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
        <vers num="2.1.8"/>
        <vers num="2.1.9"/>
        <vers num="2.1.10"/>
        <vers num="2.1.11"/>
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0824" seq="2001-0824" published="2001-12-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html">20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2969" adv="1" patch="1">2969</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="3.0.2"/>
        <vers num="3.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0825" seq="2001-0825" published="2001-12-06" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000406" adv="1" patch="1">CLA-2001:406</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-029-01">IMNX-2001-70-029-01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-092.html" adv="1" patch="1">RHSA-2001:092</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2971" adv="1" patch="1">2971</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6804">xinetd-zero-length-bo(6804)</ref>
    </refs>
    <vuln_soft>
      <prod name="xinetd" vendor="xinetd">
        <vers num="2.1.8.8"/>
        <vers num="2.1.8.9"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0826" seq="2001-0826" published="2001-12-06" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html">20010704 CesarFTPd, Cerberus FTPd</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/20010630093621.66913.qmail@web13002.mail.yahoo.com" adv="1">20010630 cesarFTP v0.98b 'HELP' buffer overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2972" adv="1">2972</ref>
    </refs>
    <vuln_soft>
      <prod name="cesarftp" vendor="aclogic">
        <vers num="0.98b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0827" seq="2001-0827" published="2001-12-06" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00070.html">20010704 CesarFTPd, Cerberus FTPd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2976" adv="1" patch="1">2976</ref>
    </refs>
    <vuln_soft>
      <prod name="ceberus_ftp_server" vendor="grant_averett">
        <vers num="1.0"/>
        <vers num="1.01"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.5"/>
        <vers num="1.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0828" seq="2001-0828" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which causes an error message that does not properly quote the Javascript.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html">20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.caucho.com/products/resin/changes.xtp" adv="1">http://www.caucho.com/products/resin/changes.xtp</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/981651">VU#981651</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2981" adv="1" patch="1">2981</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6793">java-servlet-crosssite-scripting(6793)</ref>
    </refs>
    <vuln_soft>
      <prod name="resin" vendor="caucho_technology">
        <vers num="1.2.2"/>
        <vers num="1.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0829" seq="2001-0829" published="2001-12-06" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html">20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability</ref>
      <ref source="MISC" url="http://jakarta.apache.org/tomcat/tomcat-3.2-doc/readme" adv="1" patch="1">http://jakarta.apache.org/tomcat/tomcat-3.2-doc/readme</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2982" adv="1" patch="1">2982</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0830" seq="2001-0830" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://213.146.38.146/pub/wojtekka/6tunnel-0.09.tar.gz">ftp://213.146.38.146/pub/wojtekka/6tunnel-0.09.tar.gz</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100386451702966&amp;w=2">20011023 Remote DoS in 6tunnel</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3467">3467</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7337">6tunnel-open-socket-dos(7337)</ref>
    </refs>
    <vuln_soft>
      <prod name="6tunnel" vendor="pld">
        <vers num="0.08" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0831" seq="2001-0831" published="2001-12-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100386756715645&amp;w=2">20011023 FW: ASI Oracle Security Alert: 3 new security alerts</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/OLS817alert.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/OLS817alert.pdf</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7344.php">oracle-label-security-access(7344)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3465">3465</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.1.7"/>
        <vers num="9.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0832" seq="2001-0832" published="2001-12-06" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100386756715645&amp;w=2">20011023 FW: ASI Oracle Security Alert: 3 new security alerts</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="9.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0833" seq="2001-0833" published="2001-12-06" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100386756715645&amp;w=2">20011023 FW: ASI Oracle Security Alert: 3 new security alerts</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/201295">20010802 vulnerability in otrcrep binary in Oracle 8.0.5.</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/222612">20011024 Oracle Trace Collection Security Vulnerability</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/otrcrep.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/otrcrep.pdf</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-011.shtml">M-011</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3139">3139</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6940">oracle-binary-symlink(6940)</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="9.0.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0834" seq="2001-0834" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000429" adv="1" patch="1">CLA-2001:429</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100260195401753&amp;w=2">20011007 Re: Bug found in ht://Dig htsearch CGI</ref>
      <ref source="MISC" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=458013&amp;group_id=4593&amp;atid=104593">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=458013&amp;group_id=4593&amp;atid=104593</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-035.0.txt">CSSA-2001-035.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-080" adv="1" patch="1">DSA-080</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-083.php3">MDKSA-2001:083</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_035_htdig_txt.html">SuSE-SA:2001:035</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-139.html">RHSA-2001:139</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3410">3410</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7262">htdig-htsearch-infinite-loop(7262)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7263">htdig-htsearch-retrieve-files(7263)</ref>
    </refs>
    <vuln_soft>
      <prod name="htdig" vendor="htdig">
        <vers num="3.1.5" prev="1"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0835" seq="2001-0835" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html" adv="1" patch="1">SuSE-SA:2001:040</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100394630702875&amp;w=2">20011024 Cross-site Scripting Flaw in webalizer</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1677.html">ESA-20011101-01</ref>
      <ref source="CONFIRM" url="http://www.mrunix.net/webalizer/news.html" adv="1" patch="1">http://www.mrunix.net/webalizer/news.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-140.html">RHSA-2001:140</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-141.html" adv="1" patch="1">RHSA-2001:141</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3473" adv="1" patch="1">3473</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7350">webalizer-html-tag-host(7350)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7351">webalizer-html-tags-keywords(7351)</ref>
    </refs>
    <vuln_soft>
      <prod name="webalizer" vendor="bradford_barrett">
        <vers num="2.0.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0836" seq="2001-0836" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100342151132277&amp;w=2">20011018 def-2001-30</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100395487007578&amp;w=2">20011024 Oracle9iAS Web Cache Overflow Vulnerability</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/webcache.pdf">http://otn.oracle.com/deploy/security/pdf/webcache.pdf</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-29.html">CA-2001-29</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/649979">VU#649979</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7306">oracle-appserver-http-bo(7306)</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server_web_cache" vendor="oracle">
        <vers num="2.0.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0837" seq="2001-0837" published="2001-12-06" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100403691432052&amp;w=2">20011025 Pc-to-Phone vulnerability - broken by design</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3475" adv="1">3475</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7393">pc2phone-temp-account-readable(7393)</ref>
    </refs>
    <vuln_soft>
      <prod name="pc-to-phone" vendor="deltathree">
        <vers num="3.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0838" seq="2001-0838" published="2001-12-06" modified="2017-07-11" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100402652724815&amp;w=2">20011025 RWhoisd remote format string vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="rwhoisd" vendor="network_solutions">
        <vers num="1.5.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0839" seq="2001-0839" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100404371423927&amp;w=2">20011025 Weak authentication in iBill's Password Management CGI</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3476">3476</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7352">ibillpm-cgi-insecure-password(7352)</ref>
    </refs>
    <vuln_soft>
      <prod name="processing_plus" vendor="ibill_internet_billing_company">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0840" seq="2001-0840" published="2001-12-06" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="COMPAQ" url="http://www.compaq.com/products/servers/management/mgtsw-advisory.html" adv="1" patch="1">SSRT0766</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7411.php">compaq-insightmanager-xe-bo(7411)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/908611">VU#908611</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3482" adv="1" patch="1">3482</ref>
    </refs>
    <vuln_soft>
      <prod name="insight_manager_xe" vendor="compaq">
        <vers num="1.0"/>
        <vers num="1.21"/>
        <vers num="2.1"/>
        <vers num="2.1b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0841" seq="2001-0841" published="2001-12-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100446445208739&amp;w=2">20011030 Ikonboard Cookie filter vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7433.php">ikonboard-cookie-auth-privileges(7433)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3486">3486</ref>
    </refs>
    <vuln_soft>
      <prod name="ikonboard" vendor="ikonboard.com">
        <vers num="ib219" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0842" seq="2001-0842" published="2001-12-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Search.cgi in Leoboard LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100446455809273&amp;w=2">20011030 LB5000 Cookie filter vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7436.php">leoboard-cookie-auth-privileges(7436)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3484">3484</ref>
    </refs>
    <vuln_soft>
      <prod name="lb5000" vendor="leoboard">
        <vers num="1029" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0843" seq="2001-0843" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://archives.neohapsis.com/archives/linux/conectiva/2001-q3/0020.html">CLA-2001:426</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100109679010256&amp;w=2">20010921 squid DoS</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-077">DSA-077</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-088.php3">MDKSA-2001:088</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_037_squid_txt.html">SuSE-SA:2001:037</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-113.html" adv="1" patch="1">RHSA-2001:113</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3354">3354</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7157">squid-mkdir-put-dos(7157)</ref>
    </refs>
    <vuln_soft>
      <prod name="squid_web_proxy" vendor="squid">
        <vers num="2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0844" seq="2001-0844" published="2001-12-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100446263601021&amp;w=2">20011030 cgi vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7434.php">bookofguests-cgi-command-execution(7434)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7435.php">postit-cgi-command-execution(7435)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3483">3483</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3485">3485</ref>
    </refs>
    <vuln_soft>
      <prod name="book_of_guests" vendor="seth_leonard">
        <vers num=""/>
      </prod>
      <prod name="post_it" vendor="seth_leonard">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0845" seq="2001-0845" published="2001-12-06" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="COMPAQ" url="http://ftp.support.compaq.com/patches/.new/html/SSRT0738.shtml" adv="1" patch="1">SSRT0738</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3492">3492</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7425">openvms-dms-unauthorized-access(7425)</ref>
    </refs>
    <vuln_soft>
      <prod name="dec_openvms" vendor="dec">
        <vers num="6.2_vax"/>
        <vers num="7.1_vax"/>
        <vers num="7.2_vax"/>
        <vers num="7.3_vax"/>
      </prod>
      <prod name="dec_openvms_alpha" vendor="dec">
        <vers num="6.2"/>
        <vers num="7.1.2"/>
        <vers num="7.2.1h1"/>
        <vers num="7.2.2"/>
        <vers num="7.3"/>
      </prod>
      <prod name="sevms" vendor="dec">
        <vers num="6.2"/>
      </prod>
      <prod name="sevms_alpha" vendor="dec">
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0846" seq="2001-0846" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100448721830960&amp;w=2">20011030 Lotus Domino Web Administrator Template ReplicaID Access (#NISR29102001A)</ref>
      <ref source="BID" url="http://www.iss.net/security_center/static/7424.php">3491</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7424">lotus-domino-replicaid-access(7424)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino" vendor="lotus">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.2a"/>
        <vers num="5.0.2c"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.4a"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7"/>
        <vers num="5.0.7a"/>
        <vers num="5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0847" seq="2001-0847" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100448726831108&amp;w=2">20011031 Lotus Domino Default Navigator Protection By-pass (#NISR29102001B)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3488">3488</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7423">lotus-domino-navigator-access(7423)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_web_server" vendor="lotus">
        <vers num="5.x"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0848" seq="2001-0848" published="2001-12-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100463832209281&amp;w=2">20011101 Fuse Talk vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7445.php">fusetalk-joincfm-sql-execution(7445)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3496">3496</ref>
    </refs>
    <vuln_soft>
      <prod name="fuse_talk" vendor="e-zone_media">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0849" seq="2001-0849" published="2001-12-06" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100463639800515&amp;w=2">20011101 Vulnerability in Viralator proxy extension</ref>
      <ref source="MISC" url="http://viralator.loddington.com/changes.html" adv="1">http://viralator.loddington.com/changes.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3495" patch="1">3495</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7440">viralator-cgi-command-execution(7440)</ref>
    </refs>
    <vuln_soft>
      <prod name="viralator" vendor="duncan_hall">
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9_pre1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0850" seq="2001-0850" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-037.0.txt" adv="1" patch="1">CSSA-2001-037.0</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7427">openlinux-libdb-bo(7427)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux" vendor="caldera">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0851" seq="2001-0851" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000432">CLA-2001:432</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-038.0.txt" adv="1" patch="1">CSSA-2001-38.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3">MDKSA-2001:082</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1683.html" adv="1" patch="1">ESA-20011106-01</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_039_kernel2_txt.html">SuSE-SA:2001:039</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-142.html">RHSA-2001:142</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7461">linux-syncookie-bypass-filter(7461)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_server" vendor="caldera">
        <vers num="3.1"/>
      </prod>
      <prod name="openlinux_workstation" vendor="caldera">
        <vers num="3.1"/>
      </prod>
      <prod name="openlinux" vendor="caldera">
        <vers num="2.3"/>
      </prod>
      <prod name="openlinux_edesktop" vendor="caldera">
        <vers num="2.4"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="2.3.1"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0"/>
        <vers num="2.2.0"/>
        <vers num="2.4.0"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0852" seq="2001-0852" published="2001-12-06" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100498100112191&amp;w=2">20011105 RH Linux Tux HTTPD DoS</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=tux-list&amp;m=100584714702328&amp;w=2">http://marc.info/?l=tux-list&amp;m=100584714702328&amp;w=2</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-142.html" adv="1">RHSA-2001:142</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3506">3506</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7464">tux-http-host-dos(7464)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0853" seq="2001-0853" published="2001-12-06" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-11/0022.html" adv="1" patch="1">20011105 Entrust Bulletin E01-005: GetAccess Access Service vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100498111712723&amp;w=2">20011105 New getAccess[tm] Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/243243">VU#243243</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3508">3508</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7474">getaccess-shellscripts-retrieve-files(7474)</ref>
    </refs>
    <vuln_soft>
      <prod name="getaccess" vendor="entrust">
        <vers num="all_versions"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0854" seq="2001-0854" published="2001-12-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100525739116093&amp;w=2">20011105 Copying and Deleting Files Using PHP-Nuke</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7478.php">phpnuke-filemanager-gain-privileges(7478)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3510">3510</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0855" seq="2001-0855" published="2001-12-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100528623328037&amp;w=2">20011109 ClearCase db_loader TERM environment variable buffer overflow vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7488.php">clearcase-dbloader-term-bo(7488)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3523">3523</ref>
    </refs>
    <vuln_soft>
      <prod name="clearcase" vendor="rational_software">
        <vers num="3.2_plus"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0856" seq="2001-0856" published="2001-12-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100533053219673&amp;w=2">20011109 Extracting a 3DES key from an IBM 4758</ref>
      <ref source="MISC" url="http://www.cl.cam.ac.uk/~rnc1/descrack/" adv="1" patch="1">http://www.cl.cam.ac.uk/~rnc1/descrack/</ref>
      <ref source="MISC" url="http://www.cl.cam.ac.uk/~rnc1/descrack/attack.html" adv="1">http://www.cl.cam.ac.uk/~rnc1/descrack/attack.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3524">3524</ref>
    </refs>
    <vuln_soft>
      <prod name="4758" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0857" seq="2001-0857" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000437">CLA-2001:437</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100535679608486&amp;w=2">20011109 Imp Webmail session hijacking vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100540578822469&amp;w=2">20011110 IMP 2.2.7 (SECURITY) released</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-039.0.txt">CSSA-2001-039.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3525">3525</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7496">imp-css-steal-cookies(7496)</ref>
    </refs>
    <vuln_soft>
      <prod name="webmail" vendor="imp">
        <vers num="2.2.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0858" seq="2001-0858" published="2001-12-06" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.32/" adv="1" patch="1">CSSA-2001-SCO.32</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100562386012917&amp;w=2">20011113 Security Update: [CSSA-2001-SCO.32] Open UNIX, UnixWare 7: buffer overflow in ppp utilities</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7570.php">unixware-openunix-ppp-bo(7570)</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="caldera">
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
      <prod name="openunix" vendor="caldera">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0859" seq="2001-0859" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://online.securityfocus.com/advisories/3725">HPSBTL0112-006</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-148.html" adv="1" patch="1">RHSA-2001:148</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3527">3527</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7549">linux-korean-default-umask(7549)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0860" seq="2001-0860" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100578220002083&amp;w=2">20011114 Xato Advisory: Win2k/XP Terminal Services IP Spoofing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3541">3541</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7538">win-terminal-spoof-address(7538)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0861" seq="2001-0861" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco 12000 with IOS 12.0 and line cards based on Engine 2 and earlier allows remote attackers to cause a denial of service (CPU consumption) by flooding the router with traffic that generates a large number of ICMP Unreachable replies.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-018.shtml">M-018</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/GSR-unreachables-pub.shtml" adv="1" patch="1">20011114 ICMP Unreachable Vulnerability in Cisco 12000 Series Internet Router</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3534">3534</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7536">cisco-icmp-unreachable-dos(7536)</ref>
    </refs>
    <vuln_soft>
      <prod name="12000_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0862" seq="2001-0862" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-018.shtml">M-018</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml" adv="1">20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3535">3535</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7550">cisco-acl-noninital-dos(7550)</ref>
    </refs>
    <vuln_soft>
      <prod name="12000_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0863" seq="2001-0863" published="2001-12-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not handle the "fragment" keyword in a compiled ACL (Turbo ACL) for packets that are sent to the router, which allows remote attackers to cause a denial of service via a flood of fragments.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-018.shtml">M-018</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml" adv="1">20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3539">3539</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7551">cisco-acl-outgoing-fragment(7551)</ref>
    </refs>
    <vuln_soft>
      <prod name="12000_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0864" seq="2001-0864" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly handle the implicit "deny ip any any" rule in an outgoing ACL when the ACL contains exactly 448 entries, which can allow some outgoing packets to bypass access restrictions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-018.shtml">M-018</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml" adv="1" patch="1">20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3536">3536</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7553">cisco-acl-deny-ip(7553)</ref>
    </refs>
    <vuln_soft>
      <prod name="12000_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0865" seq="2001-0865" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not support the "fragment" keyword in an outgoing ACL, which could allow fragmented packets in violation of the intended access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-018.shtml">M-018</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml" adv="1" patch="1">20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3540">3540</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7552">cisco-turbo-acl-dos(7552)</ref>
    </refs>
    <vuln_soft>
      <prod name="12000_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0866" seq="2001-0866" published="2001-12-06" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco 12000 with IOS 12.0 and lines card based on Engine 2 does not properly handle an outbound ACL when an input ACL is not configured on all the interfaces of a multi port line card, which could allow remote attackers to bypass the intended access controls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-018.shtml">M-018</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml">20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7554.php">cisco-input-acl-configured(7554)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3537">3537</ref>
    </refs>
    <vuln_soft>
      <prod name="12000_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0867" seq="2001-0867" published="2001-12-06" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not properly filter does not properly filter packet fragments even when the "fragment" keyword is used in an ACL, which allows remote attackers to bypass the intended access controls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-018.shtml">M-018</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/GSR-ACL-pub.shtml">20011114 Multiple Vulnerabilities in Access Control List Implementation for Cisco 12000 Series Internet Router</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3538">3538</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7555">cisco-acl-fragment-bypass(7555)</ref>
    </refs>
    <vuln_soft>
      <prod name="12000_router" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0868" seq="2001-0868" published="2001-11-28" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold-status.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100654958131854&amp;w=2">20011123 Redhat Stronghold Secure Server File System Disclosure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3577">3577</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/51950">apache-strongholdinfo-info-disclosure(51950)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/51951">apache-strongholdstatus-info-disclosure(51951)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7582">stronghold-webserver-obtain-information(7582)</ref>
    </refs>
    <vuln_soft>
      <prod name="stronghold" vendor="redhat">
        <vers num="2.3"/>
        <vers num="3.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0869" seq="2001-0869" published="2001-12-21" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:15.cyrus-sasl.asc">FreeBSD-SA-02:15</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000444">CLA-2001:444</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:018">MDKSA-2002:018</ref>
      <ref source="SUSE" url="http://lwn.net/alerts/SuSE/SuSE-SA%3A2001%3A042.php3" adv="1" patch="1">SuSE-SA:2001:042</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-040.0.txt">CSSA-2001-040.0</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-150.html" adv="1" patch="1">RHSA-2001:150</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-151.html" adv="1" patch="1">RHSA-2001:151</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3498">3498</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7443">cyrus-sasl-format-string(7443)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_workstation" vendor="caldera">
        <vers num="3.1"/>
      </prod>
      <prod name="linux_powertools" vendor="redhat">
        <vers num="6.2"/>
      </prod>
      <prod name="openlinux_eserver" vendor="caldera">
        <vers num="3.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
        <vers num="7.2"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0870" seq="2001-0870" published="2001-12-21" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100715758109838&amp;w=2">20011130 Rapid 7 Advisory R7-0002: Alchemy Eye Remote Unauthenticated Log Viewing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3598" adv="1" patch="1">3598</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7630">alchemy-http-view-log(7630)</ref>
    </refs>
    <vuln_soft>
      <prod name="alchemy_eye" vendor="alchemy_lab">
        <vers num="1.9"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.6.18"/>
      </prod>
      <prod name="alchemy_network_monitor" vendor="dek_software">
        <vers num="2.6.18" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0871" seq="2001-0871" published="2001-12-21" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100714173510535&amp;w=2">20011129 Rapid 7 Advisory R7-0001: Alchemy Eye HTTP Remote Command Execution</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/220715">VU#220715</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3599" adv="1">3599</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7625">alchemy-http-dot-commands(7625)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7626">alchemy-http-dot-variant(7626)</ref>
    </refs>
    <vuln_soft>
      <prod name="alchemy_eye" vendor="alchemy_lab">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.6"/>
        <vers num="2.6.18"/>
        <vers num="2.6.19"/>
        <vers num="3.0"/>
        <vers num="3.0.10"/>
      </prod>
      <prod name="alchemy_network_monitor" vendor="dek_software">
        <vers num="3.0.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0872" seq="2001-0872" published="2001-12-21" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-042.1.txt">CSSA-2001-042.1</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000446">CLA-2001:446</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:092">MDKSA-2001:092</ref>
      <ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2001-Dec/0001.html" adv="1" patch="1">SuSE-SA:2001:045</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100749779131514&amp;w=2">20011204 [Fwd: OpenSSH 3.0.2 fixes UseLogin vulnerability]</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=openssh-unix-dev&amp;m=100747128105913&amp;w=2">http://marc.info/?l=openssh-unix-dev&amp;m=100747128105913&amp;w=2</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-026.shtml">M-026</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-091">DSA-091</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/157447">VU#157447</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-161.html" adv="1" patch="1">RHSA-2001:161</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3614">3614</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0112-005">HPSBUX0112-005</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7647">openssh-uselogin-execute-code(7647)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.0.1" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0873" seq="2001-0873" published="2001-12-21" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000425" adv="1" patch="1">CLA-2001:425</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100715446131820">20011130 Redhat 7.0 local root (via uucp) (attempt 2)</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-165.html">RHSA-2001:165</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-033.0.txt" adv="1" patch="1">CSSA-2001-033.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-079">DSA-079</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_038_uucp_txt.html">SuSE-SA:2001:38</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212892" adv="1">20010908 Multiple vendor 'Taylor UUCP' problems.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3312" adv="1" patch="1">3312</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7099">uucp-argument-gain-privileges(7099)</ref>
    </refs>
    <vuln_soft>
      <prod name="taylor_uucp" vendor="ian_lance_taylor">
        <vers num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0874" seq="2001-0874" published="2001-12-13" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6.0 allow remote attackers to read certain files via HTML that passes information from a frame in the client's domain to a frame in the web site's domain, a variant of the "Frame Domain Verification" vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-027.shtml">M-027</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3693" adv="1" patch="1">3693</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-058">MS01-058</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7702">ie-frame-verification-variant2(7702)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0875" seq="2001-0875" published="2001-11-26" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245594" adv="1" patch="1">20011126 File extensions spoofable in MSIE download dialog</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3597" adv="1" patch="1">3597</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-058">MS01-058</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7636">ie-file-download-ext-spoof(7636)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1014">oval:org.mitre.oval:def:1014</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0876" seq="2001-0876" published="2001-12-20" modified="2018-10-12" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100887440810532&amp;w=2">20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=100887271006313&amp;w=2">20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-37.html" adv="1" patch="1">CA-2001-37</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-030.shtml">M-030</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/951555">VU#951555</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3723" adv="1" patch="1">3723</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-059">MS01-059</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7721">win-upnp-notify-bo(7721)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0877" seq="2001-0877" published="2001-12-20" modified="2018-10-12" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100887440810532&amp;w=2">20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=100887271006313&amp;w=2">20011220 Multiple Remote Windows XP/ME/98 Vulnerabilities</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-37.html" adv="1" patch="1">CA-2001-37</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-030.shtml">M-030</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/411059">VU#411059</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/249238" adv="1">20020109 UPNP Denial of Service</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3724">3724</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-059">MS01-059</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7722">win-upnp-udp-dos(7722)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0879" seq="2001-0879" published="2001-12-20" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100891252317406&amp;w=2">20011221 @stake advisory: Multiple overflow and format string vulnerabilities in in Microsoft SQL Server</ref>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a122001-1.txt" adv="1" patch="1">A122001-1</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3732" adv="1" patch="1">3732</ref>
      <ref source="MS" url="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-060">MS01-060</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7725">mssql-c-runtime-format-string(7725)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A253">oval:org.mitre.oval:def:253</ref>
    </refs>
    <vuln_soft>
      <prod name="sql_server" vendor="microsoft">
        <vers num="7.0"/>
        <vers num="2000"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0884" seq="2001-0884" published="2001-12-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-168.html">RHSA-2001:168</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-169.html">RHSA-2001:169</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-170.html">RHSA-2001:170</ref>
      <ref source="CONECTIVA" url="http://www.securityfocus.com/advisories/3721" adv="1" patch="1">CLA-2001:445</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/242839" adv="1" patch="1">20011128 Cgisecurity.com Advisory #7: Mailman Email Archive Cross Site Scripting</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3602">3602</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7617">mailman-java-css(7617)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0886" seq="2001-0886" published="2001-12-21" modified="2018-05-02" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000447">CLA-2002:447</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-037-01">IMNX-2001-70-037-01</ref>
      <ref source="MISC" url="http://sources.redhat.com/ml/bug-glibc/2001-11/msg00109.html">http://sources.redhat.com/ml/bug-glibc/2001-11/msg00109.html</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-029.shtml">M-029</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2002/dsa-103">DSA-103</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-095.php3">MDKSA-2001:095</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1752.html">ESA-20011217-01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-160.html" adv="1" patch="1">RHSA-2001:160</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245956">20011217 [Global InterSec 2001121001] glibc globbing issues.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3707">3707</ref>
      <ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBTL0112-008">HPSBTL0112-008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7705">glibc-glob-bo(7705)</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0887" seq="2001-0887" published="2002-01-15" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">xSANE 0.81 and earlier allows local users to modify files of other xSANE users via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-171.html">RHSA-2001:171</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-172.html">RHSA-2001:172</ref>
      <ref source="FREEBSD" url="http://www.securityfocus.com/advisories/3734" adv="1" patch="1">FreeBSD-SA-01:68</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3700" adv="1" patch="1">3700</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7714">xsane-temp-symlink(7714)</ref>
    </refs>
    <vuln_soft>
      <prod name="xsane" vendor="oliver_rauch">
        <vers num="0.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0888" seq="2001-0888" published="2001-12-21" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Atmel Firmware 1.3 Wireless Access Point (WAP) allows remote attackers to cause a denial of service via a SNMP request with (1) a community string other than "public" or (2) an unknown OID, which causes the WAP to deny subsequent SNMP requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100895903202798&amp;w=2">20011221 VIGILANTe advisory 2001003 : Atmel SNMP Non Public Community String DoS Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3734" adv="1">3734</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7734">atmel-snmp-community-dos(7734)</ref>
    </refs>
    <vuln_soft>
      <prod name="firmware" vendor="atmel">
        <vers num="1.3"/>
      </prod>
      <prod name="wap11" vendor="linksys">
        <vers num="1.3"/>
      </prod>
      <prod name="me102" vendor="netgear">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0889" seq="2001-0889" published="2001-12-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which could allow remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100877978506387&amp;w=2">20011219 [ph10@cus.cam.ac.uk: [Exim] Potential security problem]</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2002/dsa-097">DSA-097</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/283723">VU#283723</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-176.html" adv="1" patch="1">RHSA-2001:176</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3728">3728</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7738">exim-pipe-hostname-commands(7738)</ref>
    </refs>
    <vuln_soft>
      <prod name="exim" vendor="university_of_cambridge">
        <vers num="3.22" prev="1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0890" seq="2001-0890" published="2001-12-11" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-171.html" adv="1" patch="1">RHSA-2001:171</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7714.php" adv="1" patch="1">xsane-temp-symlink(7714)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3987">3987</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="sane">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0891" seq="2001-0891" published="2002-01-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020101-01-I" adv="1" patch="1">20020101-01-I</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100695627423924&amp;w=2">20011127 UNICOS LOCAL HOLE ALL VERSIONS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3590">3590</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7618">unicos-nqsd-format-string(7618)</ref>
    </refs>
    <vuln_soft>
      <prod name="nqsdaemon" vendor="sgi">
        <vers num="3.3.0.16"/>
      </prod>
      <prod name="unicos" vendor="cray">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0892" seq="2001-0892" published="2001-11-13" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100568999726036&amp;w=2">20011113 Cgisecurity.com Advisory #6: thttpd and mini_http Permission bypass vuln</ref>
      <ref source="CONFIRM" url="http://www.acme.com/software/thttpd/" adv="1">http://www.acme.com/software/thttpd/</ref>
    </refs>
    <vuln_soft>
      <prod name="thttpd" vendor="acme_labs">
        <vers num="2.22" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0893" seq="2001-0893" published="2001-11-13" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100568999726036&amp;w=2">20011113 Cgisecurity.com Advisory #6: thttpd and mini_http Permission bypass vuln</ref>
      <ref source="CONFIRM" url="http://www.acme.com/software/mini_httpd/" adv="1">http://www.acme.com/software/mini_httpd/</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7541.php">httpd-bypass-permissions(7541)</ref>
    </refs>
    <vuln_soft>
      <prod name="mini_httpd" vendor="acme_labs">
        <vers num="1.16" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0894" seq="2001-0894" published="2001-11-11" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in Postfix SMTP server before 20010228-pl07, when configured to email the postmaster when SMTP errors cause the session to terminate, allows remote attackers to cause a denial of service (memory exhaustion) by generating a large number of SMTP errors, which forces the SMTP session log to grow too large.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000439">CLA-2001:439</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:089">MDKSA-2001:089</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100584160110303&amp;w=2">20011115 Postfix session log memory exhaustion bugfix</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-093" patch="1">DSA-093</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-156.html">RHSA-2001:156</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3544" adv="1" patch="1">3544</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7568">postfix-smtp-log-dos(7568)</ref>
    </refs>
    <vuln_soft>
      <prod name="postfix" vendor="wietse_venema">
        <vers num="1999-09-06"/>
        <vers num="1999-12-31"/>
        <vers num="2000-02-28"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0895" seq="2001-0895" published="2001-11-15" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to overwrite the MAC address in its ARP table.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/IOS-arp-overwrite-vuln-pub.shtml" adv="1" patch="1">20011115 Cisco IOS ARP Table Overwrite Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/399355">VU#399355</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3547">3547</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7547">cisco-arp-overwrite-table(7547)</ref>
    </refs>
    <vuln_soft>
      <prod name="catalyst_2900xl" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_2948g-l3" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_2950" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_3500xl" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_3550" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_4000" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_4908g-l3" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_5000" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_6000" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="catalyst_8500" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="distributed_director" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0896" seq="2001-0896" published="2001-11-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Inetd in OpenServer 5.0.5 allows remote attackers to cause a denial of service (crash) via a port scan, e.g. with nmap -PO.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.33/CSSA-2001-SCO.33.txt" adv="1">CSSA-2001-SCO.33</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101284101228656&amp;w=2">20020201 RE: DoS bug on Tru64</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101303877215098&amp;w=2">20020205 nmap vs. inetd on Caldera (ex-SCO) OpenServer, Re: DoS bug on Tru64</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7571">openserver-nmap-po-option(7571)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0897" seq="2001-0897" published="2001-11-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100586033530341&amp;w=2">20011115 UBB vulnerablietis + about: using example</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100586541317940&amp;w=2">20011115 Re: UBB vulnerablietis + about: using example</ref>
    </refs>
    <vuln_soft>
      <prod name="ultimate_bulletin_board" vendor="infopop">
        <vers num="5.47e" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0898" seq="2001-0898" published="2001-11-15" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript that uses setTimeout to (1) access data after a new window to the domain has been opened or (2) access data via about:cache.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100586079932284&amp;w=2">20011115 Several javascript vulnerabilities in Opera</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100588139312696&amp;w=2">20011116 Re: Several javascript vulnerabilities in Opera</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7567.php">opera-java-cross-site(7567)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3553">3553</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="6.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0899" seq="2001-0899" published="2001-11-16" modified="2019-07-01" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100593523104176&amp;w=2">20011116 Network Tool 0.2 Addon for PHPNuke vulnerable to remote command execution</ref>
      <ref source="CONFIRM" url="http://phpnukerz.org/modules.php?name=Downloads&amp;d_op=viewsdownload&amp;sid=32" patch="1">http://phpnukerz.org/modules.php?name=Downloads&amp;d_op=viewsdownload&amp;sid=32</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7578">phpnuke-nettools-command-execution(7578)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="phpnuke">
        <vers num=""/>
      </prod>
      <prod name="network_tools" vendor="rick_fournier">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0900" seq="2001-0900" published="2001-11-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the include parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100619599000590&amp;w=2">20011118 Gallery Addon for PhpNuke remote file viewing vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3554">3554</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7580">phpnuke-gallery-directory-traversal(7580)</ref>
    </refs>
    <vuln_soft>
      <prod name="gallery" vendor="francisco_burzi">
        <vers num="1.2.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0901" seq="2001-0901" published="2001-11-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100626603407639&amp;w=2">20011119 Hypermail SSI Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.hypermail.org/dist/hypermail-2.1.4.tar.gz" adv="1">http://www.hypermail.org/dist/hypermail-2.1.4.tar.gz</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7576">hypermail-ssi-execute-commands(7576)</ref>
    </refs>
    <vuln_soft>
      <prod name="hypermail" vendor="hypermail_development">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0902" seq="2001-0902" published="2001-11-20" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100626531103946&amp;w=2">20011120 IIS logging issue</ref>
      <ref source="NTBUGTRAQ" url="http://marc.info/?l=ntbugtraq&amp;m=100627497122247&amp;w=2">20011120 IIS logging issue</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6795" adv="1">6795</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7613">iis-fake-log-entry(7613)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0903" seq="2001-0903" published="2001-11-20" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100626641009560&amp;w=2">20011120 A Cryptanalysis of the High-bandwidth Digital Content Protection System</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7612.php">hdcp-authentication-keys(7612)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3558">3558</ref>
    </refs>
    <vuln_soft>
      <prod name="high-bandwidth_digital_content_protection" vendor="intel">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0904" seq="2001-0904" published="2001-11-20" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100619268115798&amp;w=2">20011120 MSIE 5.5/6 Q312461 patch disclose patch information</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7581.php">ie-q312461-patch-existence(7581)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3556">3556</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0905" seq="2001-0905" published="2001-10-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal while a signal handling routine is already running.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:60.procmail.asc" adv="1" patch="1">FreeBSD-SA-01:60</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000433">CLA-2001:433</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-083" adv="1" patch="1">DSA-083</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-085.php3" adv="1" patch="1">MDKSA-2001:085</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-093.html" adv="1" patch="1">RHSA-2001:093</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3071" adv="1" patch="1">3071</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6872">procmail-signal-handling-race(6872)</ref>
    </refs>
    <vuln_soft>
      <prod name="procmail" vendor="procmail">
        <vers num="3.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0906" seq="2001-0906" published="2001-06-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-030-01">IMNX-2001-70-030-01</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-086.php3" adv="1" patch="1">MDKSA-2001:086</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-102.html" adv="1" patch="1">RHSA-2001:102</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/192647" adv="1">20010622 LPRng + tetex tmpfile race - uid lp exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2974" adv="1" patch="1">2974</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6785">tetex-lprng-tmp-race(6785)</ref>
    </refs>
    <vuln_soft>
      <prod name="tetex" vendor="tetex">
        <vers num="1.0.7.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0907" seq="2001-0907" published="2001-10-18" modified="2018-09-20" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt">CSSA-2001-036.0</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01">IMNX-2001-70-035-01</ref>
      <ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:079" adv="1">MDKSA-2001:079</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100343090106914&amp;w=2" adv="1">20011018 Flaws in recent Linux kernels</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100350685431610&amp;w=2" adv="1">20011019 TSLSA-2001-0028</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7312.php">linux-multiple-symlink-dos(7312)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3">MDKSA-2001:082</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1650.html" adv="1">ESA-20011019-02</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_036_kernel_txt.html">SuSE-SA:2001:036</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3444" adv="1">3444</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.16" edition="pre5"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17" edition="pre14"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3" edition="pre3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0908" seq="2001-0908" published="2001-11-21" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638693315933&amp;w=2">20011121 CITRIX &amp; Microsoft Windows Terminal Services False IP Address Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3566" adv="1">3566</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7538">win-terminal-spoof-address(7538)</ref>
    </refs>
    <vuln_soft>
      <prod name="metaframe" vendor="citrix">
        <vers num="1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0909" seq="2001-0909" published="2001-11-21" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638955422011&amp;w=2">20011121 Buffer overflow in Windows XP "helpctr.exe"</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6802" adv="1">6802</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7605">winxp-helpctr-bo(7605)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0910" seq="2001-0910" published="2001-11-21" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638782917917&amp;w=2">20011121 Legato Networker vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3564" adv="1">3564</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7601">networker-reverse-dns-bypass-auth(7601)</ref>
    </refs>
    <vuln_soft>
      <prod name="networker" vendor="emc">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0911" seq="2001-0911" published="2001-11-21" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638850219503&amp;w=2">20011121 PhpNuke Admin password can be stolen !</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3567" adv="1">3567</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7596">phpnuke-postnuke-insecure-passwords(7596)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3.1"/>
      </prod>
      <prod name="postnuke" vendor="postnuke_software_foundation">
        <vers num="0.64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0912" seq="2001-0912" published="2001-11-30" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-087.php3?dis=8.1" adv="1" patch="1">MDKSA-2001:087</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7604">linux-expect-unauth-root(7604)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0913" seq="2001-0913" published="2001-11-22" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.research.netsol.com/pipermail/rwhois-announce/2001-November/000023.html" adv="1" patch="1">http://lists.research.netsol.com/pipermail/rwhois-announce/2001-November/000023.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100655265508104&amp;w=2">20011122 [NetGuard Security] NSI Rwhoisd another Remote Format String Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod name="rwhoisd" vendor="network_solutions">
        <vers num="1.5"/>
        <vers num="1.5.1a"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.7.1"/>
        <vers num="1.5.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0914" seq="2001-0914" published="2001-11-21" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Linux kernel before 2.4.11pre3 in multiple Linux distributions allows local users to cause a denial of service (crash) by starting the core vmlinux kernel, possibly related to poor error checking during ELF loading.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638584813349&amp;w=2">20011121 SuSE 7.3 : Kernel 2.4.10-4GB Bug</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100654787226869&amp;w=2L:2">20011122 Re: SuSE 7.3 : Kernel 2.4.10-4GB Bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3570" adv="1">3570</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7591">linux-vmlinux-dos(7591)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.11" prev="1" edition="pre3"/>
      </prod>
      <prod name="suse_linux" vendor="suse">
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0915" seq="2001-0915" published="2001-11-21" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638919720975&amp;w=2">20011121 Advisory: Berkeley pmake</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7602.php">pmake-shell-format-string(7602)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3572">3572</ref>
    </refs>
    <vuln_soft>
      <prod name="pmake" vendor="berkeley">
        <vers num="2.1.33" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0916" seq="2001-0916" published="2001-11-21" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638919720975&amp;w=2">20011121 Advisory: Berkeley pmake</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7603.php">pmake-shell-bo(7603)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3573">3573</ref>
    </refs>
    <vuln_soft>
      <prod name="pmake" vendor="berkeley">
        <vers num="2.1.33" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0917" seq="2001-0917" published="2001-11-22" modified="2019-03-25" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Jakarta Tomcat 4.0.1 allows remote attackers to reveal physical path information by requesting a long URL with a .JSP extension.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100654722925155&amp;w=2">20011122 Hi</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=tomcat-dev&amp;m=100658457507305&amp;w=2">http://marc.info/?l=tomcat-dev&amp;m=100658457507305&amp;w=2</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7599">tomcat-reveal-install-path(7599)</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5@%3Cdev.tomcat.apache.org%3E">[tomcat-dev] 20190319 svn commit: r1855831 [21/30] - in /tomcat/site/trunk: ./ docs/ xdocs/</ref>
      <ref source="MLIST" url="https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74@%3Cdev.tomcat.apache.org%3E">[tomcat-dev] 20190325 svn commit: r1856174 [19/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0918" seq="2001-0918" published="2001-11-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerabilities in CGI scripts in susehelp in SuSE 7.2 and 7.3 allow remote attackers to execute arbitrary commands by not opening files securely.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_041_susehelp_txt.html">SuSE-SA:2001:041</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3576" adv="1" patch="1">3576</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7583">susehelp-cgi-command-execution(7583)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="7.2"/>
        <vers num="7.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0919" seq="2001-0919" published="2001-11-26" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100679857614967&amp;w=2">20011126 Javascript can bypass user preference for cookie prompt in IE5.50.4134.0100</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0920" seq="2001-0920" published="2001-11-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in auto nice daemon (AND) 1.0.4 and earlier allows a local user to possibly execute arbitrary code via a process name containing a format string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://and.sourceforge.net/" adv="1">http://and.sourceforge.net/</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100680319004162&amp;w=2">20011126 [CERT-intexxia] Auto Nice Daemon Format String Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3580" adv="1" patch="1">3580</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7606">and-format-string(7606)</ref>
    </refs>
    <vuln_soft>
      <prod name="autonice_daemon" vendor="patrick_schemitz">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0921" seq="2001-0921" published="2001-11-21" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100638816318705&amp;w=2">20011121 Mac Netscape password fields</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3565" adv="1">3565</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7593">macos-netscape-print-passwords(7593)</ref>
    </refs>
    <vuln_soft>
      <prod name="communicator" vendor="netscape">
        <vers num="4.77" prev="1" edition=":macos"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0922" seq="2001-0922" published="2001-11-26" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100681274915525&amp;w=2">20011126 NMRC Advisory - NetDynamics Session ID is Reusable</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3583" adv="1" patch="1">3583</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7620">netdynamics-session-hijacking(7620)</ref>
    </refs>
    <vuln_soft>
      <prod name="netdynamics" vendor="sun">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.1.2"/>
        <vers num="4.1.3"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0923" seq="2001-0923" published="2001-10-25" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000440">CLA-2001:440</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/222542" adv="1">20011025 Advisory: Corrupt RPM Query Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3472" adv="1" patch="1">3472</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7349">Linux-rpm-execute-code(7349)</ref>
    </refs>
    <vuln_soft>
      <prod name="redhat_package_manager" vendor="redhat">
        <vers num="4.0.2-71"/>
        <vers num="4.0.2-72"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0924" seq="2001-0924" published="2001-11-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100654890029878&amp;w=2">20011122 double dot vulnerability on a site running Informix database.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100688672019635&amp;w=2">20011127 Re: double dot vulnerability on a site running Informix database.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3575" adv="1" patch="1">3575</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7585">informix-web-datablade-directory-traversal(7585)</ref>
    </refs>
    <vuln_soft>
      <prod name="informix_web_datablade" vendor="ibm">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="4.10"/>
        <vers num="4.11"/>
        <vers num="4.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0925" seq="2001-0925" published="2001-03-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.apacheweek.com/features/security-13">http://www.apacheweek.com/features/security-13</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-067">DSA-067</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3" adv="1" patch="1">MDKSA-2001:077</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1452.html">ESA-20010620-02</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/168497" adv="1" patch="1">20010312 FORW: [ANNOUNCE] Apache 1.3.19 Released</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/178066">20010419 OpenBSD 2.8patched Apache vuln!</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/193081" adv="1">20010624 Fw: Bugtraq ID 2503 : Apache Artificially Long Slash Path Directory Listing Exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2503" adv="1" patch="1">2503</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;start=2002-01-27&amp;end=2002-02-02&amp;mid=199857&amp;threads=1">20010726 Apache Artificially Long Slash Path Directory Listing Vulnerabili ty -- FILE READ ACCESS</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6921">apache-slash-directory-listing(6921)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0926" seq="2001-0926" published="2001-11-28" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100697797325013&amp;w=2">20011128 JRun SSI Request Body Parsing</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&amp;Method=Full" adv="1" patch="1">http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&amp;Method=Full</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3589" adv="1" patch="1">3589</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7622">allaire-jrun-view-source(7622)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.3"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0927" seq="2001-0927" published="2001-11-27" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100689302316077&amp;w=2">20011127 [CERT-intexxia] libgtop_daemon Remote Format String Vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2002/dsa-098" adv="1" patch="1">DSA-098</ref>
    </refs>
    <vuln_soft>
      <prod name="libgtop_daemon" vendor="gnome">
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.9"/>
        <vers num="1.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0928" seq="2001-0928" published="2001-11-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100699007010203&amp;w=2">20011128 Re: [CERT-intexxia] libgtop_daemon Remote Format String Vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2002/dsa-098" adv="1" patch="1">DSA-098</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-301" adv="1" patch="1">DSA-301</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/705771" adv="1">VU#705771</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3594">3594</ref>
    </refs>
    <vuln_soft>
      <prod name="libgtop_daemon" vendor="gnome">
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.9"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0929" seq="2001-0929" published="2001-11-28" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml" adv="1" patch="1">20011128 A Vulnerability in IOS Firewall Feature Set</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/362483">VU#362483</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3588">3588</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7614">ios-cbac-bypass-acl(7614)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="11.2p"/>
        <vers num="11.3t"/>
        <vers num="12.0"/>
        <vers num="12.0t"/>
        <vers num="12.1"/>
        <vers num="12.1e"/>
        <vers num="12.1t"/>
        <vers num="12.2"/>
        <vers num="12.2t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0930" seq="2001-0930" published="2001-11-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sendpage.pl allows remote attackers to execute arbitrary commands via a message containing shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100689313216624&amp;w=2">20011128 Sendpage (Perl CGI) Remote Execution Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7609.php">sendpage-message-command-execution(7609)</ref>
    </refs>
    <vuln_soft>
      <prod name="sendpage.pl" vendor="sendpage">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0931" seq="2001-0931" published="2001-11-28" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100698397818175&amp;w=2">20011128 PowerFTP-server-Bugs&amp;Exploits-Remotes</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3593" adv="1">3593</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7615">powerftp-dot-directory-traversal(7615)</ref>
    </refs>
    <vuln_soft>
      <prod name="powerftp" vendor="cooolsoft">
        <vers num="2.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0932" seq="2001-0932" published="2001-11-28" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100698397818175&amp;w=2">20011128 PowerFTP-server-Bugs&amp;Exploits-Remotes</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3595" adv="1">3595</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7616">powerftp-long-command-dos(7616)</ref>
    </refs>
    <vuln_soft>
      <prod name="powerftp" vendor="cooolsoft">
        <vers num="2.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0933" seq="2001-0933" published="2001-11-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100698397818175&amp;w=2">20011128 PowerFTP-server-Bugs&amp;Exploits-Remotes</ref>
    </refs>
    <vuln_soft>
      <prod name="powerftp" vendor="cooolsoft">
        <vers num="2.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0934" seq="2001-0934" published="2001-11-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100698397818175&amp;w=2">20011128 PowerFTP-server-Bugs&amp;Exploits-Remotes</ref>
    </refs>
    <vuln_soft>
      <prod name="powerftp" vendor="cooolsoft">
        <vers num="2.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0935" seq="2001-0935" published="2001-11-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_043_wuftpd_txt.html">SuSE-SA:2001:043</ref>
    </refs>
    <vuln_soft>
      <prod name="wu-ftpd" vendor="washington_university">
        <vers num="2.4"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0936" seq="2001-0936" published="2001-11-30" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Frox transparent FTP proxy 0.6.6 and earlier, with the local caching method selected, allows remote FTP servers to run arbitrary code via a long response to an MDTM request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://frox.sourceforge.net/security.txt" adv="1">http://frox.sourceforge.net/security.txt</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100713367307799&amp;w=2">20011130 Alert: Vulnerability in frox transparent ftp proxy.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3606" adv="1" patch="1">3606</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7632">frox-ftp-proxy-bo(7632)</ref>
    </refs>
    <vuln_soft>
      <prod name="frox" vendor="frox">
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3"/>
        <vers num="0.6.4"/>
        <vers num="0.6.5"/>
        <vers num="0.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0937" seq="2001-0937" published="2001-11-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100714269114686&amp;w=2">20011130 Vulnerabilities in PGPMail.pl</ref>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/243262" adv="1">20011129 PGPMail.pl possible remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod name="pgpmail.pl" vendor="matt_wright">
        <vers num="1.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0938" seq="2001-0938" published="2001-11-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100715294425985&amp;w=2">20011130 Aspupload installs exploitable scripts</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7628.php">aspupload-upload-directory-traversal(7628)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7629.php">aspupload-directory-browsing-download(7629)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3608">3608</ref>
    </refs>
    <vuln_soft>
      <prod name="aspupload" vendor="persits">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0939" seq="2001-0939" published="2001-11-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100715316426817&amp;w=2">20011130 Denial of Service in Lotus Domino 5.08 and earlier HTTP Server</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3607" adv="1" patch="1">3607</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/manager.wss?rs=0&amp;rt=0&amp;org=sims&amp;doc=4C8E450DBF2E7F1885256B200079FA88" adv="1" patch="1">http://www-1.ibm.com/support/manager.wss?rs=0&amp;rt=0&amp;org=sims&amp;doc=4C8E450DBF2E7F1885256B200079FA88</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7631">lotus-domino-nhttp-dos(7631)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino" vendor="lotus">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0940" seq="2001-0940" published="2001-09-21" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbitrary code via a long user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2001-q3/0151.html" adv="1" patch="1">20010921 Check Point FireWall-1 GUI Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00291.html">20011130 Fw: Firewall-1 remote SYSTEM shell buffer overflow</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100094268017271&amp;w=2">20010919 Check Point FireWall-1 GUI Log Viewer vulnerability (vuldb 3336)</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100698954308436&amp;w=2">20011128 Firewall-1 remote SYSTEM shell buffer overflow</ref>
      <ref source="CHECKPOINT" url="http://www.checkpoint.com/techsupport/alerts/buffer_overflow.html">20010919 GUI Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3336">3336</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7145">fw1-log-viewer-bo(7145)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0941" seq="2001-0941" published="2001-11-30" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100716693806967&amp;w=2">20011130 ASI Oracle Security Alert: Oracle Home Environment Variable Buffer Overflow</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3138">3138</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7643">oracle-dbsnmp-home-bo(7643)</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.0.6"/>
        <vers num="8.1.6"/>
        <vers num="8.1.7"/>
        <vers num="9.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0942" seq="2001-0942" published="2001-11-29" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf" adv="1" patch="1">http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2001/Dec/0000.html">20011130 ASI Oracle Security Alert: Oracle Home Environment Variable Validation Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3137">3137</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7645">oracle-dbsnmp-home-validation(7645)</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.1.6"/>
        <vers num="8.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0943" seq="2001-0943" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf">http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2001/Dec/0001.html">20011130 ASI Oracle Security Alert: CHOWN Path Environment Variable Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201020" adv="1" patch="1">20010801 Oracle 8.1.5 dbnsmp vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3129" adv="1" patch="1">3129</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.0.5"/>
        <vers num="8.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0944" seq="2001-0944" published="2001-12-02" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100734173831990&amp;w=2">20011202 mIRC bug?</ref>
    </refs>
    <vuln_soft>
      <prod name="mirc" vendor="khaled_mardam-bey">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0945" seq="2001-0945" published="2001-12-03" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100741295502017&amp;w=2">20011203 Buffer over flow on Outlook express for Macintosh</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7648.php">macos-outlook-long-message-bo(7648)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3611">3611</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0946" seq="2001-0946" published="2001-12-04" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100743394701962&amp;w=2">20011204 Symlink attack with apmd of RH 7.2</ref>
      <ref source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=56389" adv="1">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=56389</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8268">apmd-apmscript-symlink(8268)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0947" seq="2001-0947" published="2001-12-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100749428517090&amp;w=2">20011204 NMRC Advisory - Multiple Valicert Problems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3615" adv="1" patch="1">3615</ref>
      <ref source="CONFIRM" url="http://www.valicert.com/support/security_advisory_eva.html" adv="1">http://www.valicert.com/support/security_advisory_eva.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7649">eva-forms-reveal-path(7649)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_validation_authority" vendor="valicert">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0948" seq="2001-0948" published="2001-12-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100749428517090&amp;w=2">20011204 NMRC Advisory - Multiple Valicert Problems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3619" adv="1" patch="1">3619</ref>
      <ref source="CONFIRM" url="http://www.valicert.com/support/security_advisory_eva.html" adv="1">http://www.valicert.com/support/security_advisory_eva.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7650">eva-admin-script-injection(7650)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_validation_authority" vendor="valicert">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0949" seq="2001-0949" published="2001-12-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100749428517090&amp;w=2">20011204 NMRC Advisory - Multiple Valicert Problems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3621" adv="1" patch="1">3621</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3622">3622</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3624">3624</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3625">3625</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3627">3627</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3628">3628</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3629">3629</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3630">3630</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3631">3631</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3632">3632</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3633">3633</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3634">3634</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3635">3635</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3636">3636</ref>
      <ref source="CONFIRM" url="http://www.valicert.com/support/security_advisory_eva.html" adv="1">http://www.valicert.com/support/security_advisory_eva.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7652">eva-forms-bo(7652)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_validation_authority" vendor="valicert">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0950" seq="2001-0950" published="2001-12-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100749428517090&amp;w=2">20011204 NMRC Advisory - Multiple Valicert Problems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3618" adv="1" patch="1">3618</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3620" adv="1" patch="1">3620</ref>
      <ref source="CONFIRM" url="http://www.valicert.com/support/security_advisory_eva.html">http://www.valicert.com/support/security_advisory_eva.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7651">eva-insecure-key-storage(7651)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7653">eva-insecure-key-generation(7653)</ref>
    </refs>
    <vuln_soft>
      <prod name="enterprise_validation_authority" vendor="valicert">
        <vers num="3.3"/>
        <vers num="3.4"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="3.8"/>
        <vers num="3.9"/>
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0951" seq="2001-0951" published="2001-12-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100774842520403&amp;w=2">20011207 UDP DoS attack in Win2k via IKE</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100813081913496&amp;w=2">20011211 UDP DoS attack in Win2k via IKE</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3652" adv="1">3652</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7667">win2k-ike-dos(7667)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0952" seq="2001-0952" published="2001-12-07" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via packets to UDP port 7755.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100774266027774&amp;w=2">20011207 Red Faction Server/Client DOS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3651" adv="1">3651</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7672">red-faction-udp-dos(7672)</ref>
    </refs>
    <vuln_soft>
      <prod name="red_faction" vendor="volition">
        <vers num="1.0"/>
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0953" seq="2001-0953" published="2001-12-08" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Kebi WebMail allows remote attackers to access the administrator menu and gain privileges via the /a/ hidden directory, which is installed under the web document root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100780264902037&amp;w=2:1">20011208 kebi-Webmail Solution vulnerability (Tested)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3655" adv="1">3655</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7674">kebi-webmail-admin-dir-access(7674)</ref>
    </refs>
    <vuln_soft>
      <prod name="kebi_community" vendor="nara_vision">
        <vers num="1.0_academy"/>
        <vers num="1.0_enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0954" seq="2001-0954" published="2001-12-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Lotus Domino 5.0.5 and 5.0.8, and possibly other versions, allows remote attackers to cause a denial of service (block access to databases that have not been previously accessed) via a URL that includes the . (dot) directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100780146532131&amp;w=2L:1">20011207 Lotus Domino Web server vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3656" adv="1">3656</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/manager.wss?rs=1&amp;rt=0&amp;org=sims&amp;doc=255CC03D83CFF50C85256B1E005E349B">http://www-1.ibm.com/support/manager.wss?rs=1&amp;rt=0&amp;org=sims&amp;doc=255CC03D83CFF50C85256B1E005E349B</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7684">lotus-domino-database-dos(7684)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino" vendor="lotus">
        <vers num="5.0.5"/>
        <vers num="5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0955" seq="2001-0955" published="2001-09-22" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://cvsweb.xfree86.org/cvsweb/xc/programs/Xserver/fb/fbglyph.c">http://cvsweb.xfree86.org/cvsweb/xc/programs/Xserver/fb/fbglyph.c</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100776624224549&amp;w=2">20011207 Crashing X</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100784290015880&amp;w=2">20011208 Re: Crashing X</ref>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=100118958310463&amp;w=2">20010922 XFree86 DOS / Buffer overflow local and remote.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3657" adv="1" patch="1">3657</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3663" adv="1">3663</ref>
      <ref source="CONFIRM" url="http://www.xfree86.org/4.2.0/RELNOTES2.html#2">http://www.xfree86.org/4.2.0/RELNOTES2.html#2</ref>
      <ref source="CONFIRM" url="http://www.xfree86.org/security/">http://www.xfree86.org/security/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7673">xfree86-konqueror-bo(7673)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7683">xfree86-xterm-title-bo(7683)</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0956" seq="2001-0956" published="2001-09-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0089.html" patch="1">20010911 security alert: speechd from speechio.org</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3326" adv="1" patch="1">3326</ref>
      <ref source="CONFIRM" url="http://www.speechio.org/speechd.html" adv="1">http://www.speechio.org/speechd.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7121">speechd-execute-commands(7121)</ref>
    </refs>
    <vuln_soft>
      <prod name="speechd" vendor="speechio">
        <vers num="0.54" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0958" seq="2001-0958" published="2001-09-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in eManager plugin for Trend Micro InterScan VirusWall for NT 3.51 and 3.51J allow remote attackers to execute arbitrary code via long arguments to the CGI programs (1) register.dll, (2) ContentFilter.dll, (3) SFNofitication.dll, (4) register.dll, (5) TOP10.dll, (6) SpamExcp.dll, and (7) spamrule.dll.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0099.html" adv="1" patch="1">20010912 [SNS Advisory No.42] Trend Micro InterScan eManager for NT Multiple Program Buffer Overflow Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3327" adv="1" patch="1">3327</ref>
      <ref source="MISC" url="http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=3142">http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=3142</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7104">interscan-emanager-bo(7104)</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_emanager" vendor="trend_micro">
        <vers num="3.51"/>
        <vers num="3.51_j"/>
      </prod>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.0.1"/>
        <vers num="3.2.3"/>
        <vers num="3.3"/>
        <vers num="3.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0959" seq="2001-0959" published="2001-09-15" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwrite critical files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0137.html" adv="1">20010915 ARCserve 6.61 Share Access Vulnerability</ref>
      <ref source="MISC" url="http://support.ca.com/Download/patches/asitnt/QO00945.html" patch="1">http://support.ca.com/Download/patches/asitnt/QO00945.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3342" adv="1" patch="1">3342</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7122">arcserve-aremote-plaintext(7122)</ref>
    </refs>
    <vuln_soft>
      <prod name="arcserve_backup" vendor="ca">
        <vers num="6.61" edition="sp2a"/>
      </prod>
      <prod name="arcserve_backup_2000" vendor="ca">
        <vers num="" edition=":advanced"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0960" seq="2001-0960" published="2001-09-15" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0137.html" adv="1">20010915 ARCserve 6.61 Share Access Vulnerability</ref>
      <ref source="MISC" url="http://support.ca.com/Download/patches/asitnt/QO00945.html" patch="1">http://support.ca.com/Download/patches/asitnt/QO00945.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3343" adv="1" patch="1">3343</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7122">arcserve-aremote-plaintext(7122)</ref>
    </refs>
    <vuln_soft>
      <prod name="arcserve_backup" vendor="ca">
        <vers num="6.61" edition="sp2a"/>
      </prod>
      <prod name="arcserve_backup_2000" vendor="ca">
        <vers num="" edition=":advanced"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0961" seq="2001-0961" published="2001-09-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-076" adv="1" patch="1">DSA-076</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3347" adv="1" patch="1">3347</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7149">most-file-create-bo(7149)</ref>
    </refs>
    <vuln_soft>
      <prod name="most" vendor="john_e._davis">
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.9.0"/>
        <vers num="4.9.1"/>
        <vers num="4.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0962" seq="2001-0962" published="2001-09-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM WebSphere Application Server 3.02 through 3.53 uses predictable session IDs for cookies, which allows remote attackers to gain privileges of WebSphere users via brute force guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0234.html">20010928 Re: Websphere cookie/sessionid predictable</ref>
      <ref source="CONFIRM" url="http://www14.software.ibm.com/webapp/download/postconfig.jsp?id=4000805&amp;pf=Multi-Platform&amp;v=3.0.2&amp;e=Standard+%26+Advanced+Editions&amp;cat=&amp;s=p">http://www14.software.ibm.com/webapp/download/postconfig.jsp?id=4000805&amp;pf=Multi-Platform&amp;v=3.0.2&amp;e=Standard+%26+Advanced+Editions&amp;cat=&amp;s=p</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7153">ibm-websphere-seq-predict(7153)</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="3.5.3" prev="1"/>
      </prod>
      <prod name="websphere_commerce_suite" vendor="ibm">
        <vers num="3.1.2"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0963" seq="2001-0963" published="2001-09-20" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SpoonFTP 1.1 allows local and sometimes remote attackers to access files outside of the FTP root via a ... (modified dot dot) in the CD (CWD) command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0171.html" adv="1" patch="1">20010920 Vulnerability in SpoonFTP</ref>
      <ref source="CONFIRM" url="http://www.pi-soft.com/spoonftp/index.shtml" adv="1" patch="1">http://www.pi-soft.com/spoonftp/index.shtml</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3351">3351</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7147">spoonftp-dot-directory-traversal(7147)</ref>
    </refs>
    <vuln_soft>
      <prod name="spoonftp" vendor="pi-soft">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0964" seq="2001-0964" published="2001-09-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0178.html" adv="1">20010920 Advisory: Half-Life remote buffer overflow vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7148">halflife-connect-bo(7148)</ref>
    </refs>
    <vuln_soft>
      <prod name="half-life" vendor="valve_software">
        <vers num="1.1.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0965" seq="2001-0965" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0239.html" adv="1" patch="1">20010817 [ASGUARD-LABS] glFTPD v1.23 DOS Attack</ref>
      <ref source="CONFIRM" url="http://www.glftpd.org/" adv="1">http://www.glftpd.org/</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7001.php">glftpd-list-dos(7001)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3201" adv="1" patch="1">3201</ref>
    </refs>
    <vuln_soft>
      <prod name="glftpd" vendor="glftpd">
        <vers num="1.13.6"/>
        <vers num="1.16.9"/>
        <vers num="1.17.2"/>
        <vers num="1.18a"/>
        <vers num="1.19"/>
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22b"/>
        <vers num="1.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0966" seq="2001-0966" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0232.html" adv="1">20010818 [Real Security] Advisory for Nudester 1.10</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3202" adv="1" patch="1">3202</ref>
    </refs>
    <vuln_soft>
      <prod name="nudester" vendor="nudester.org">
        <vers num="1.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0967" seq="2001-0967" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0228.html">20010817 Arkeia Possible remote root &amp; information leakage</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3204" adv="1" patch="1">3204</ref>
    </refs>
    <vuln_soft>
      <prod name="arkeia" vendor="knox_software">
        <vers num="4.2"/>
        <vers num="4.2.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0968" seq="2001-0968" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0228.html">20010817 Arkeia Possible remote root &amp; information leakage</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3203">3203</ref>
    </refs>
    <vuln_soft>
      <prod name="arkeia" vendor="knox_software">
        <vers num="4.2"/>
        <vers num="4.2.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0969" seq="2001-0969" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:53.ipfw.asc" adv="1" patch="1">FreeBSD-SA-01:53</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3206" adv="1" patch="1">3206</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7002">ipfw-me-unauthorized-access(7002)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0970" seq="2001-0970" published="2001-08-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0281.html">20010820 Re: tdforum 1.2 Messageboard</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99832137410609&amp;w=2">20010820 tdforum 1.2 Messageboard</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/782243" adv="1">VU#782243</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3207">3207</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7009">tdforum-cross-site-scripting(7009)</ref>
    </refs>
    <vuln_soft>
      <prod name="td_forum" vendor="tdavid">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0971" seq="2001-0971" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7010.php">4d-webserver-directory-traversal(7010)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/206102" adv="1">20010820 ACI 4D WebServer Directory traversal.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3209" adv="1">3209</ref>
    </refs>
    <vuln_soft>
      <prod name="4d_webserver" vendor="aci">
        <vers num="6.5.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0972" seq="2001-0972" published="2001-08-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99834088223352&amp;w=2">20010820 security problem in surf-net ASP Discussion Forum &lt; 2.30</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3210" adv="1" patch="1">3210</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7011">surfnet-asp-cookie-seq-predictable(7011)</ref>
    </refs>
    <vuln_soft>
      <prod name="asp_forum" vendor="surf-net">
        <vers num="2.20"/>
        <vers num="2.30" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0973" seq="2001-0973" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0328.html" adv="1" patch="1">20010822 BSCW symlink vulnerability</ref>
      <ref source="CONFIRM" url="http://bscw.gmd.de/Bulletins/BSCW-SB-2001-08.extract.txt" adv="1" patch="1">http://bscw.gmd.de/Bulletins/BSCW-SB-2001-08.extract.txt</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7029.php">bscw-extracted-file-symlink(7029)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/465971">VU#465971</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3227">3227</ref>
    </refs>
    <vuln_soft>
      <prod name="bscw" vendor="fraunhofer_fit">
        <vers num="3.3"/>
        <vers num="3.3.1"/>
        <vers num="3.4.1"/>
        <vers num="3.4.3"/>
        <vers num="4.0.1_beta"/>
        <vers num="4.0.2_beta" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0974" seq="2001-0974" published="2001-07-17" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1" patch="1">CA-2001-18</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/869184" adv="1" patch="1">VU#869184</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3048" adv="1" patch="1">3048</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6903">oracle-ldap-protos-format-string(6903)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_directory" vendor="oracle">
        <vers num="2.1.1"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0975" seq="2001-0975" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/oid_cert_bof.pdf">http://otn.oracle.com/deploy/security/pdf/oid_cert_bof.pdf</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1" patch="1">CA-2001-18</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/869184" adv="1" patch="1">VU#869184</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3047" adv="1" patch="1">3047</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6902">oracle-ldap-protos-bo(6902)</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_directory" vendor="oracle">
        <vers num="2.1.1"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0976" seq="2001-0976" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q3/0048.html" adv="1" patch="1">HPSBUX0108-165</ref>
    </refs>
    <vuln_soft>
      <prod name="process_resource_manager" vendor="hp">
        <vers num="c.01.08.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0977" seq="2001-0977" published="2001-07-16" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000417">CLA-2001:417</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1" patch="1">CA-2001-18</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-068">DSA-068</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/935800" adv="1" patch="1">VU#935800</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-069.php3" adv="1" patch="1">MDKSA-2001:069</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-098.html">RHSA-2001:098</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3049" adv="1" patch="1">3049</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6904">openldap-ldap-protos-dos(6904)</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_single_network_firewall" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
      <prod name="openldap" vendor="openldap">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.2.8"/>
        <vers num="1.2.9"/>
        <vers num="1.2.10"/>
        <vers num="1.2.11"/>
        <vers num="1.2.12"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="8.0"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0978" seq="2001-0978" published="2001-09-03" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">login in HP-UX 10.26 does not record failed login attempts in /var/adm/btmp, which could allow attackers to conduct brute force password guessing attacks without being detected or observed using the lastb program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HPBUG" url="http://archives.neohapsis.com/archives/hp/2001-q3/0052.html" patch="1">PHCO_17719</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8632.php">hpux-login-btmp(8632)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3289" adv="1" patch="1">3289</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0979" seq="2001-0979" published="2001-09-03" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/211687">20010903 hpux warez</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3279" adv="1" patch="1">3279</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7078">hpux-swverify-bo(7078)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0980" seq="2001-0980" published="2001-07-17" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">docview before 1.0-15 allows remote attackers to execute arbitrary commands via shell metacharacters that are processed when converting a man page to a web page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-026.0.txt" adv="1" patch="1">CSSA-2001-026.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3052" adv="1">3052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6854">docview-httpd-command-execution(6854)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_server" vendor="caldera">
        <vers num="3.1"/>
      </prod>
      <prod name="openlinux_workstation" vendor="caldera">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0981" seq="2001-0981" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q3/0048.html" adv="1" patch="1">HPSBUX0108-164</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7051">hp-cifs-change-passwords(7051)</ref>
    </refs>
    <vuln_soft>
      <prod name="cifs-9000_server" vendor="hp">
        <vers num="a.01.07" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0982" seq="2001-0982" published="2001-07-23" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.tivoli.com/support/patches/patches_3.7.1/3.7.1-POL-0003/3.7.1-POL-0003.README" adv="1" patch="1">ftp://ftp.tivoli.com/support/patches/patches_3.7.1/3.7.1-POL-0003/3.7.1-POL-0003.README</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0497.html" adv="1" patch="1">20010723 iXsecurity.20010618.policy_director.a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3080" adv="1" patch="1">3080</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY18152&amp;apar=only">IY18152</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6884">tivoli-secureway-dot-directory-traversal(6884)</ref>
    </refs>
    <vuln_soft>
      <prod name="tivoli_secureway_policy_director" vendor="ibm">
        <vers num="3.0.1"/>
        <vers num="3.6"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0983" seq="2001-0983" published="2001-08-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99861651923668&amp;w=2">20010823 Re: Respondus v1.1.2 stores passwords using weak encryption</ref>
      <ref source="MISC" url="http://www.eve-software.com/security/ueditpw.html" adv="1">http://www.eve-software.com/security/ueditpw.html</ref>
    </refs>
    <vuln_soft>
      <prod name="ultraedit-32" vendor="ultraedit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0984" seq="2001-0984" published="2001-09-13" modified="2017-12-19" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213931" adv="1">20010913 leak of information in counterpane/Bruce Schneier's Password Safe program</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3337" adv="1">3337</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7123">counterpane-password-access(7123)</ref>
    </refs>
    <vuln_soft>
      <prod name="password_safe" vendor="counterpane">
        <vers num="1.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0985" seq="2001-0985" published="2001-09-08" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.irata.com/shopver.html" patch="1">http://www.irata.com/shopver.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212827" adv="1">20010908 Shopping Cart Version 1.23</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3308" adv="1">3308</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7106">hassan-cart-command-execution(7106)</ref>
    </refs>
    <vuln_soft>
      <prod name="shopping_cart" vendor="hassan_consulting">
        <vers num="1.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0986" seq="2001-0986" published="2001-09-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/214217" adv="1" patch="1">20010914 Security Vulnerability with Microsoft Index Server 2.0(Sample file reveals file info, physical path etc)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3339" adv="1">3339</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7125">winnt-indexserver-sqlqhit-asp(7125)</ref>
    </refs>
    <vuln_soft>
      <prod name="index_server" vendor="microsoft">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0987" seq="2001-0987" published="2001-07-22" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on other web clients by causing the Javascript to be inserted into error messages that are generated by CGIWrap.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0499.html" adv="1">20010722 Re: [cgiwrap-users] Re: Security hole in CGIWrap (cross-site scripting vulnerability)</ref>
      <ref source="CONFIRM" url="http://cgiwrap.sourceforge.net/changes.html" patch="1">http://cgiwrap.sourceforge.net/changes.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3084" adv="1" patch="1">3084</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6886">cgiwrap-cross-site-scripting(6886)</ref>
    </refs>
    <vuln_soft>
      <prod name="cgiwrap" vendor="nathan_neulinger">
        <vers num="3.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0988" seq="2001-0988" published="2001-07-23" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0521.html" adv="1">20010723 permission probs with Arkeia</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3085" adv="1">3085</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6885">arkeia-insecure-file-permissions(6885)</ref>
    </refs>
    <vuln_soft>
      <prod name="arkeia" vendor="knox_software">
        <vers num="4.2.8.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0989" seq="2001-0989" published="2001-07-23" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0512.html" patch="1">20010723 pileup 1.2</ref>
      <ref source="CONFIRM" url="http://www.babbage.demon.co.uk/linux/pileup-1.2/pileup-1.2.tar.gz">http://www.babbage.demon.co.uk/linux/pileup-1.2/pileup-1.2.tar.gz</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3086" adv="1" patch="1">3086</ref>
    </refs>
    <vuln_soft>
      <prod name="pileup" vendor="richard_everitt">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0990" seq="2001-0990" published="2001-09-04" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.inter7.com/vpopmail/ChangeLog">http://www.inter7.com/vpopmail/ChangeLog</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212036" adv="1" patch="1">20010904 BUZ.CH Security Advisory 200109041: Inter7 vpopmail DB pw problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3284" adv="1">3284</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7076">vpopmail-insecure-auth-data(7076)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpopmail" vendor="inter7">
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.4.10"/>
        <vers num="3.4.11"/>
        <vers num="3.4.11e"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.8"/>
        <vers num="4.9"/>
        <vers num="4.9.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0991" seq="2001-0991" published="2001-07-24" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/198954" adv="1" patch="1">20010724 Proxomitron Cross-site Scripting Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3087" adv="1" patch="1">3087</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6887">proxomitron-cross-site-scripting(6887)</ref>
    </refs>
    <vuln_soft>
      <prod name="proxomitron_naoko-4" vendor="scott_r._lemmon">
        <vers num="beta1"/>
        <vers num="beta2"/>
        <vers num="beta3"/>
        <vers num="beta4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0992" seq="2001-0992" published="2001-09-05" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0012.html" adv="1">20010905 ShopPlus Cart</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7077">shopplus-command-execution(7077)</ref>
    </refs>
    <vuln_soft>
      <prod name="shopplus_cart" vendor="kabotie_software_technologies">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0993" seq="2001-0993" published="2001-07-24" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="http://archives.neohapsis.com/archives/netbsd/2001-q3/0102.html" adv="1" patch="1">NetBSD-SA2001-011</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3088" adv="1" patch="1">3088</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6908">bsd-kernel-sendmsg-dos(6908)</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0994" seq="2001-0994" published="2001-09-04" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/211956" adv="1">20010904 Telnet DoS Vulnerability in Marconi ATM Switch Software</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3286" adv="1">3286</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7082">forethought-telnet-dos(7082)</ref>
    </refs>
    <vuln_soft>
      <prod name="forethought" vendor="marconi">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0995" seq="2001-0995" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHProjekt before 2.4a allows remote attackers to perform actions as other PHProjekt users by modifying the ID number in an HTTP request to PHProjekt CGI programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.phprojekt.com/ChangeLog" adv="1">http://www.phprojekt.com/ChangeLog</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/210349" adv="1" patch="1">20010826 security hole in os groupware suite PHProjekt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3239" adv="1" patch="1">3239</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7035">phprojekt-id-modify(7035)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpprojekt" vendor="phpprojekt">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
        <vers num="2.1a"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0996" seq="2001-0996" published="2001-09-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that could cause clients to crash or otherwise behave unexpectedly.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0436.html" adv="1">20010902 POP3Lite 0.2.3b minor client side DoS and message injection</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3278" adv="1" patch="1">3278</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7075">pop3lite-dot-message-injection(7075)</ref>
    </refs>
    <vuln_soft>
      <prod name="pop3lite" vendor="pop3lite">
        <vers num="0.2.3"/>
        <vers num="0.2.3b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0997" seq="2001-0997" published="2001-09-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0096.html">20010911 Textor Webmasters Ltd (listrec.pl)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7117">listrecpl-remote-command-execution(7117)</ref>
    </refs>
    <vuln_soft>
      <prod name="listrec.pl" vendor="textor_webmasters_ltd.">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0998" seq="2001-0998" published="2001-09-24" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM HACMP 4.4 allows remote attackers to cause a denial of service via a completed TCP connection to HACMP ports (e.g., using a port scan) that does not send additional data, which causes a failure in snmpd.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/216105" adv="1">20010924 HACMP and port scans</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/217910" patch="1">20011002 Vulnerability 3358, "IBM HACMP Port Scan Denial of Service Vulnerability"</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3358" adv="1" patch="1">3358</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17630&amp;apar=only">IY17630</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY20943&amp;apar=only">IY20943</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7165">hacmp-portscan-dos(7165)</ref>
    </refs>
    <vuln_soft>
      <prod name="hacmp" vendor="ibm">
        <vers num="4.4"/>
      </prod>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="4.3.3"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-0999" seq="2001-0999" published="2001-09-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213754" adv="1">20010912 FREAK SHOW: Outlook Express 6.00</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/214453" adv="1">20010915 Proof-Of-Concept Perl Script for Bugtraq-ID: #3334</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3334" adv="1">3334</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7118">outlook-express-text-script-execution(7118)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1000" seq="2001-1000" published="2001-09-07" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0036.html" adv="1">20010907 rlmadmin v3.8M view file symlink vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3302" adv="1">3302</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7096">radius-rlmadmin-help-symlink(7096)</ref>
    </refs>
    <vuln_soft>
      <prod name="aaa_radius_server" vendor="merit">
        <vers num="3.8m"/>
        <vers num="5.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1002" seq="2001-1002" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99892644616749&amp;w=2">20010827 LPRng/rhs-printfilters - remote execution of commands</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-102.html" adv="1" patch="1">RHSA-2001:102</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3241" adv="1" patch="1">3241</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/16509">dvips-lpd-command-execution(16509)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1003" seq="2001-1003" published="2001-08-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99859557930285&amp;w=2">20010823 Respondus v1.1.2 stores passwords using weak encryption</ref>
    </refs>
    <vuln_soft>
      <prod name="respondus" vendor="webct">
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1004" seq="2001-1004" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0415.html" adv="1" patch="1">20010830 gnut gnutella client html injection</ref>
    </refs>
    <vuln_soft>
      <prod name="gnutella_client" vendor="gnutella">
        <vers num="0.4.27" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1005" seq="2001-1005" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/210067" adv="1" patch="1">20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3231" adv="1">3231</ref>
    </refs>
    <vuln_soft>
      <prod name="truesync_desktop" vendor="starfish">
        <vers num="2.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1006" seq="2001-1006" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/210067" adv="1" patch="1">20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3232" adv="1">3232</ref>
    </refs>
    <vuln_soft>
      <prod name="truesync_desktop" vendor="starfish">
        <vers num="2.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1007" seq="2001-1007" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/210067" adv="1" patch="1">20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="truesync_desktop" vendor="starfish">
        <vers num="2.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1008" seq="2001-1008" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0359.html" adv="1">20010824 Java Plugin 1.4 with JRE 1.3 -> Ignores certificates.</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7048.php">javaplugin-jre-expired-certificate(7048)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3245" adv="1" patch="1">3245</ref>
    </refs>
    <vuln_soft>
      <prod name="java_plug-in" vendor="sun">
        <vers num="1.4"/>
      </prod>
      <prod name="jre" vendor="sun">
        <vers num="1.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1009" seq="2001-1009" published="2001-08-31" modified="2011-02-16" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0118.html" adv="1" patch="1">20010809 Fetchmail security advisory</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000419">CLA-2001:419</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-071">DSA-071</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6965.php">fetchmail-signed-integer-index(6965)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-072.php3">MDKSA-2001:072</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1555.html" adv="1" patch="1">ESA-20010816-01</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_026_fetchmail_txt.html">SuSE-SA:2001:026</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-103.html" adv="1" patch="1">RHSA-2001:103</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3164" adv="1" patch="1">3164</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3166" adv="1" patch="1">3166</ref>
    </refs>
    <vuln_soft>
      <prod name="fetchmail" vendor="fetchmail">
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.1.0"/>
        <vers num="5.1.4"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.3"/>
        <vers num="5.3.8"/>
        <vers num="5.4.0"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.5.0"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.6.0"/>
        <vers num="5.7.0"/>
        <vers num="5.7.2"/>
        <vers num="5.7.4"/>
        <vers num="5.8"/>
        <vers num="5.8.1"/>
        <vers num="5.8.2"/>
        <vers num="5.8.3"/>
        <vers num="5.8.4"/>
        <vers num="5.8.5"/>
        <vers num="5.8.6"/>
        <vers num="5.8.11"/>
        <vers num="5.8.13"/>
        <vers num="5.8.14" prev="1"/>
        <vers num="5.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1010" seq="2001-1010" published="2001-07-22" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) attack on the page parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0565.html" adv="1">20010721 Sambar Web Server pagecount exploit code</ref>
      <ref source="CONFIRM" url="http://www.sambar.com/security.htm" adv="1" patch="1">http://www.sambar.com/security.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3092" adv="1" patch="1">3092</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6916">sambar-pagecount-overwrite-files(6916)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="4.4"/>
        <vers num="5.0" edition="beta1"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1011" seq="2001-1011" published="2001-07-25" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0569.html" adv="1">20010725 Serious security hole in Mambo Site Server version 3.0.X</ref>
      <ref source="CONFIRM" url="http://prdownloads.sourceforge.net/mambo/mambov3.0.6.tar.gz">http://prdownloads.sourceforge.net/mambo/mambov3.0.6.tar.gz</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3093" adv="1" patch="1">3093</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6910">mambo-phpsessid-gain-privileges(6910)</ref>
    </refs>
    <vuln_soft>
      <prod name="mambo_site_server" vendor="mambo">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1012" seq="2001-1012" published="2001-09-05" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_030_screen_txt.html">SuSE-SA:2001:030</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7134">screen-local-privilege-elevation(7134)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1013" seq="2001-1013" published="2001-09-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0083.html" adv="1">20000707 (no subject)</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0087.html">20000707 Re: apache and 404/404 status codes</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0094.html" adv="1">20000707 Re: your mail</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213667" adv="1">20010912 Is there user Anna at your host ?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3335" adv="1" patch="1">3335</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7129">linux-apache-username-exists(7129)</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1014" seq="2001-1014" published="2001-09-15" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/214456" adv="1">20010915 advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3340" adv="1">3340</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7128">eshop-script-execute-commands(7128)</ref>
    </refs>
    <vuln_soft>
      <prod name="webdiscount_e_shop_online_shop_system" vendor="michael_boehme">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1015" seq="2001-1015" published="2001-10-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0107.html" adv="1" patch="1">20011016 [ ** Snes9x buffer overflow vulnerability ** ]</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3437" adv="1" patch="1">3437</ref>
    </refs>
    <vuln_soft>
      <prod name="snes9x" vendor="snes9x.com">
        <vers num="1.3.4"/>
        <vers num="1.3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1016" seq="2001-1016" published="2001-09-04" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.pgp.com/support/product-advisories/pgpsdk.asp" adv="1" patch="1">http://www.pgp.com/support/product-advisories/pgpsdk.asp</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/211806" adv="1" patch="1">20010904 PGPsdk Key Validity Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3280" adv="1" patch="1">3280</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7081">pgp-invalid-key-display(7081)</ref>
    </refs>
    <vuln_soft>
      <prod name="corporate_desktop" vendor="pgp">
        <vers num="7.1"/>
      </prod>
      <prod name="e-business_server" vendor="pgp">
        <vers num="6.5.8"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
      </prod>
      <prod name="freeware" vendor="pgp">
        <vers num="7.0.3"/>
      </prod>
      <prod name="personal_security" vendor="pgp">
        <vers num="7.0.3"/>
      </prod>
      <prod name="pgp" vendor="pgp">
        <vers num="5.0"/>
        <vers num="6.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1017" seq="2001-1017" published="2001-09-04" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and crack the passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:59.rmuser.v1.1.asc" adv="1" patch="1">FreeBSD-SA-01:59</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3282" adv="1" patch="1">3282</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7086">rmuser-insecure-password-file(7086)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1018" seq="2001-1018" published="2001-09-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100094373621813&amp;w=2">20010919 lotus domino server 5.08 is very gabby</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3350" adv="1">3350</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7180">lotus-domino-ip-reveal(7180)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino" vendor="lotus">
        <vers num="5.0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1019" seq="2001-1019" published="2001-09-08" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212825">20010908 sglMerchant Version 1.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3309" adv="1">3309</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7100">sglmerchant-dot-directory-traversal(7100)</ref>
    </refs>
    <vuln_soft>
      <prod name="sglmerchant" vendor="seaglass_technologies_inc.">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1020" seq="2001-1020" published="2001-09-05" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0013.html" adv="1">20010905 directorymanager bug</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=51589">http://sourceforge.net/project/shownotes.php?release_id=51589</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3288" adv="1">3288</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7079">directory-manager-execute-commands(7079)</ref>
    </refs>
    <vuln_soft>
      <prod name="directory_manager" vendor="vibechild">
        <vers num="0.91" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1021" seq="2001-1021" published="2001-07-26" modified="2019-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0610.html" adv="1" patch="1">20010726 def-2001-28 - WS_FTP server 2.0.2 Buffer Overflow and possible DOS</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html" patch="1">http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6911">wsftp-long-command-bo(6911)</ref>
    </refs>
    <vuln_soft>
      <prod name="ipswitch_ws_ftp_server" vendor="progress">
        <vers num="2.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1022" seq="2001-1022" published="2001-07-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000428">CLA-2001:428</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-072" adv="1" patch="1">DSA-072</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2002/dsa-107">DSA-107</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-004.html">RHSA-2002:004</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/199706" patch="1">20010727 ADV/EXP:pic/lpd remote exploit - RH 7.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3103" patch="1">3103</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6918">linux-groff-format-string(6918)</ref>
    </refs>
    <vuln_soft>
      <prod name="groff" vendor="gnu">
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.11a"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16.1"/>
      </prod>
      <prod name="jgroff" vendor="jgroff">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1023" seq="2001-1023" published="2001-09-21" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Xcache 2.1 allows remote attackers to determine the absolute path of web server documents by requesting a URL that is not cached by Xcache, which returns the full pathname in the Content-PageName header.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0182.html" adv="1">20010921 IRM Security Advisory: Xcache Path Disclosure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3352" adv="1">3352</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7159">xcache-path-disclosure(7159)</ref>
    </refs>
    <vuln_soft>
      <prod name="xcache" vendor="xcache_technologies">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1024" seq="2001-1024" published="2001-07-27" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0662.html" adv="1">20010727 Entrust - getAccess</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6915">entrust-getaccess-execute-commands(6915)</ref>
    </refs>
    <vuln_soft>
      <prod name="getaccess" vendor="entrust">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1025" seq="2001-1025" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html" adv="1">20010803 [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3149" adv="1">3149</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1026" seq="2001-1026" published="2001-07-09" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Trend Micro InterScan AppletTrap 2.0 does not properly filter URLs when they are modified in certain ways such as (1) using a double slash (//) instead of a single slash, (2) URL-encoded characters, (3) requesting the IP address instead of the domain name, or (4) using a leading 0 in an octet of an IP address.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0129.html" adv="1">20010709 Various problems in Ternd Micro AppletTrap URL filtering</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2996">2996</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2998">2998</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3000">3000</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6816">content-slash-bypass-filter(6816)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6817">applettrap-unicode-bypass-filter(6817)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6818">applettrap-bypass-ip-restrictions(6818)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6819">applettrap-zero-bypass-restrictions(6819)</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_applettrap" vendor="trend_micro">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1027" seq="2001-1027" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in WindowMaker (aka wmaker) 0.64 and earlier allows remote attackers to execute arbitrary code via a long window title.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000411">CLA-2001:411</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-074" adv="1" patch="1">DSA-074</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-074.php3">MDKSA-2001:074</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_032_wmaker_txt.html">SuSE-SA:2001:032</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3177" adv="1" patch="1">3177</ref>
      <ref source="CONFIRM" url="http://www.windowmaker.org/src/ChangeLog" adv="1">http://www.windowmaker.org/src/ChangeLog</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6969">windowmaker-title-bo(6969)</ref>
    </refs>
    <vuln_soft>
      <prod name="windowmaker" vendor="windowmaker">
        <vers num="0.60"/>
        <vers num="0.61"/>
        <vers num="0.61.1"/>
        <vers num="0.62"/>
        <vers num="0.62.1"/>
        <vers num="0.63"/>
        <vers num="0.63.1"/>
        <vers num="0.64" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1028" seq="2001-1028" published="2001-05-28" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/8622.php">man-ultimate-source-bo(8622)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-072.html" adv="1" patch="1">RHSA-2001:072</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1029" seq="2001-1029" published="2001-09-20" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0173.html">20010920 Local vulnerability in libutil derived with FreeBSD 4.4-RC (and earlier)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8697">bsd-libutil-privilege-dropping(8697)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="4.5"/>
      </prod>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1030" seq="2001-1030" published="2001-07-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0362.html" adv="1" patch="1">20010719 TSLSA-2001-0013 - Squid</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-031-01" adv="1" patch="1">IMNX-2001-70-031-01</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-029.0.txt">CSSA-2001-029.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-066.php3">MDKSA-2001:066</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-097.html" adv="1" patch="1">RHSA-2001:097</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197727" adv="1" patch="1">20010718 Squid httpd acceleration acl bug enables portscanning</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6862">squid-http-accelerator-portscanning(6862)</ref>
    </refs>
    <vuln_soft>
      <prod name="openlinux_server" vendor="caldera">
        <vers num="3.1"/>
      </prod>
      <prod name="immunix" vendor="immunix">
        <vers num="6.2"/>
        <vers num="7.0"/>
        <vers num="7.0_beta"/>
      </prod>
      <prod name="mandrake_single_network_firewall" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
      <prod name="squid_web_proxy" vendor="squid">
        <vers num="2.3stable3"/>
        <vers num="2.3stable4"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.2"/>
        <vers num="8.0"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
      <prod name="secure_linux" vendor="trustix">
        <vers num="1.01"/>
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1031" seq="2001-1031" published="2001-09-27" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0231.html" adv="1">20010927 CARTSA-2001-03 Meteor FTPD 1.0 Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3374">3374</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7176">meteor-ftpd-directory-traversal(7176)</ref>
    </refs>
    <vuln_soft>
      <prod name="meteor_ftpd" vendor="charles_clark">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1032" seq="2001-1032" published="2001-09-24" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling admin.php with an upload parameter and specifying the file to copy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0203.html" adv="1">20010924 twlc advisory: all versions of php nuke are vulnerable...</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=113892">http://sourceforge.net/forum/forum.php?forum_id=113892</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3361">3361</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7170">php-nuke-admin-file-overwrite(7170)</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="5.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1033" seq="2001-1033" published="2001-09-25" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Compaq TruCluster 1.5 allows remote attackers to cause a denial of service via a port scan from a system that does not have a DNS PTR record, which causes the cluster to enter a "split-brain" state.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/216323" adv="1">20010925 Re: HACMP and port scans</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3362" adv="1">3362</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7171">trucluster-portscan-dos(7171)</ref>
    </refs>
    <vuln_soft>
      <prod name="trucluster" vendor="compaq">
        <vers num="1.5"/>
      </prod>
      <prod name="tru64" vendor="compaq">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1034" seq="2001-1034" published="2001-09-23" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/215984">20010923 hylafax</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3357" adv="1">3357</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7164">hylafax-hostname-format-string(7164)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1035" seq="2001-1035" published="2001-09-24" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Binary decoding feature of slrn 0.9 and earlier allows remote attackers to execute commands via shell scripts that are inserted into a news post.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-078" patch="1">DSA-078</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3364" adv="1" patch="1">3364</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7166">slrn-decode-script-execution(7166)</ref>
    </refs>
    <vuln_soft>
      <prod name="slrn" vendor="slrn_development_team">
        <vers num="0.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1036" seq="2001-1036" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200991">20010801 Slackware 8.0, 7.1 Vulnerability: /usr/bin/locate</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3127" adv="1">3127</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6932">locate-command-execution(6932)</ref>
    </refs>
    <vuln_soft>
      <prod name="findutils" vendor="gnu">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
      <prod name="slackware_linux" vendor="slackware">
        <vers num="7.1"/>
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1037" seq="2001-1037" published="2001-01-08" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/SN-kernel-pub.html" adv="1" patch="1">20010711 Vulnerabilities in Cisco SN 5420 Storage Routers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3131" adv="1">3131</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6827">cisco-sn-gain-access(6827)</ref>
    </refs>
    <vuln_soft>
      <prod name="sn_5420_storage_router_firmware" vendor="cisco">
        <vers num="1.1(2)"/>
        <vers num="1.1(3)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1038" seq="2001-1038" published="2001-07-11" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-112.shtml" adv="1">L-112</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/SN-kernel-pub.html" adv="1">20010711 Vulnerabilities in Cisco SN 5420 Storage Routers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3014">3014</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6826">cisco-sn-dos(6826)</ref>
    </refs>
    <vuln_soft>
      <prod name="sn_5420_storage_router_firmware" vendor="cisco">
        <vers num="1.1(2)"/>
        <vers num="1.1(3)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1039" seq="2001-1039" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201160" adv="1">20010801 HP Jetdirect passwords don't sync</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3132" adv="1" patch="1">3132</ref>
    </refs>
    <vuln_soft>
      <prod name="jetadmin" vendor="hp">
        <vers num="4.0"/>
        <vers num="4.1.2"/>
        <vers num="5.1"/>
        <vers num="5.5"/>
        <vers num="5.5.177"/>
        <vers num="5.6"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1040" seq="2001-1040" published="2001-08-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)">
    <desc>
      <descript source="cve">HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201224" adv="1">20010802 Re: HP Jetdirect passwords don't sync</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3132" adv="1" patch="1">3132</ref>
    </refs>
    <vuln_soft>
      <prod name="jetadmin" vendor="hp">
        <vers num="4.0"/>
        <vers num="4.1.2"/>
        <vers num="5.1"/>
        <vers num="5.5"/>
        <vers num="5.5.177"/>
        <vers num="5.6"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1041" seq="2001-1041" published="2001-08-31" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100395579811880&amp;w=2">20011024 Oracle File Overwrite Security Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99677282117387&amp;w=2">20010802 vulnerability in oracle binary in Oracle 8.0.5 - 8.1.6</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf">http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3135" adv="1" patch="1">3135</ref>
    </refs>
    <vuln_soft>
      <prod name="database_server" vendor="oracle">
        <vers num="8.0"/>
        <vers num="8.1"/>
        <vers num="9.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1042" seq="2001-1042" published="2001-07-02" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194443" adv="1">20010701 Broker 5.9.5.0 Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2960" adv="1">2960</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6760">ftp-lnk-directory-traversal(6760)</ref>
    </refs>
    <vuln_soft>
      <prod name="broker_ftp_server" vendor="transsoft">
        <vers num="5.9.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1043" seq="2001-1043" published="2001-07-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194445" adv="1">20010701 ArGoSoft 1.2.2.2 *.lnk upload Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2961" adv="1">2961</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6760">ftp-lnk-directory-traversal(6760)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_server" vendor="argosoft">
        <vers num="1.2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1044" seq="2001-1044" published="2001-01-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/155897" adv="1" patch="1">20010112 Basilix Webmail System *.class *.inc Permission Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2198" adv="1" patch="1">2198</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5934">basilix-webmail-retrieve-files(5934)</ref>
    </refs>
    <vuln_soft>
      <prod name="basilix_webmail" vendor="basilix">
        <vers num="0.9.7_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1045" seq="2001-1045" published="2001-07-06" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0114.html" adv="1" patch="1">20010706 basilix bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2995" adv="1" patch="1">2995</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6873">basilix-webmail-view-files(6873)</ref>
    </refs>
    <vuln_soft>
      <prod name="basilix_webmail" vendor="basilix">
        <vers num="1.02_beta"/>
        <vers num="1.03_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1046" seq="2001-1046" published="2001-06-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q3/0006.html" adv="1" patch="1">CSSA-2001-SCO.8</ref>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=98777649031406&amp;w=2">20010420 Qpopper 4.0 Buffer Overflow</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/188267" patch="1">20010602 Qpopper 4.0.3 **** Fixes Buffer Overflow **** (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2811" adv="1" patch="1">2811</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6647">qpopper-username-bo(6647)</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1047" seq="2001-1047" published="2001-06-02" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jun/0020.html">20010602 Locally exploitable races in OpenBSD VFS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2817" adv="1">2817</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2818" adv="1">2818</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6660">openbsd-dup2-race-dos(6660)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6661">openbsd-pipe-race-dos(6661)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.6"/>
        <vers num="2.7"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1048" seq="2001-1048" published="2001-10-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html" adv="1" patch="1">20011002 results of semi-automatic source code audit</ref>
      <ref source="MISC" url="http://www.geocrawler.com/archives/3/14414/2001/9/0/6668723/">http://www.geocrawler.com/archives/3/14414/2001/9/0/6668723/</ref>
      <ref source="CONFIRM" url="http://www.gospelcom.net/mnn/topher/awol/changelog.php" patch="1">http://www.gospelcom.net/mnn/topher/awol/changelog.php</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php">php-includedir-code-execution(7215)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3387" adv="1">3387</ref>
    </refs>
    <vuln_soft>
      <prod name="awol" vendor="topher1kenobe">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="2.0"/>
        <vers num="2.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1049" seq="2001-1049" published="2001-10-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html" adv="1" patch="1">20011002 results of semi-automatic source code audit</ref>
      <ref source="CONFIRM" url="http://phorecast.org/">http://phorecast.org/</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php">php-includedir-code-execution(7215)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3388" adv="1">3388</ref>
    </refs>
    <vuln_soft>
      <prod name="phorecast" vendor="paul_m._jones">
        <vers num="0.40" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1050" seq="2001-1050" published="2001-10-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html" adv="1" patch="1">20011002 results of semi-automatic source code audit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3389" adv="1">3389</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7215">php-includedir-code-execution(7215)</ref>
    </refs>
    <vuln_soft>
      <prod name="ccc" vendor="cccsoftware">
        <vers num="0.91"/>
        <vers num="0.92"/>
        <vers num="0.94"/>
        <vers num="0.95"/>
        <vers num="0.96"/>
        <vers num="0.97"/>
        <vers num="0.98"/>
        <vers num="0.99"/>
        <vers num="1.0"/>
        <vers num="1.02"/>
        <vers num="1.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1051" seq="2001-1051" published="2001-10-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html" adv="1" patch="1">20011002 results of semi-automatic source code audit</ref>
      <ref source="MISC" url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=440666&amp;group_id=20971&amp;atid=120971" adv="1">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=440666&amp;group_id=20971&amp;atid=120971</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3390" adv="1">3390</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7215">php-includedir-code-execution(7215)</ref>
    </refs>
    <vuln_soft>
      <prod name="darkportal-unix" vendor="dark_hart_portal">
        <vers num="0.1.16"/>
        <vers num="0.1.17"/>
        <vers num="0.1.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1052" seq="2001-1052" published="2001-10-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html" adv="1" patch="1">20011002 results of semi-automatic source code audit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3391" adv="1">3391</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7215">php-includedir-code-execution(7215)</ref>
    </refs>
    <vuln_soft>
      <prod name="empris" vendor="emergenices_personnel_information_system">
        <vers num="0.4"/>
        <vers num="2001-08-10"/>
        <vers num="2001-09-08"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1053" seq="2001-1053" published="2001-07-13" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0249.html" adv="1" patch="1">20010713 AdCycle SQL Command Insertion Vulnerability - qDefense Advisory Number QDAV-2001-7-2</ref>
      <ref source="CONFIRM" url="http://www.adcycle.com/cgi-bin/download.cgi?type=UNIX&amp;version=1.17">http://www.adcycle.com/cgi-bin/download.cgi?type=UNIX&amp;version=1.17</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3032" adv="1" patch="1">3032</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6837">adcycle-insert-sql-command(6837)</ref>
    </refs>
    <vuln_soft>
      <prod name="adcycle" vendor="adcycle">
        <vers num="0.77"/>
        <vers num="0.77b"/>
        <vers num="0.78b"/>
        <vers num="1.0"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1054" seq="2001-1054" published="2001-10-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html" adv="1" patch="1">20011002 results of semi-automatic source code audit</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=117952">http://sourceforge.net/forum/forum.php?forum_id=117952</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?thread_id=148900&amp;forum_id=117952">http://sourceforge.net/forum/forum.php?thread_id=148900&amp;forum_id=117952</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php">php-includedir-code-execution(7215)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3392" adv="1" patch="1">3392</ref>
    </refs>
    <vuln_soft>
      <prod name="phpadsnew" vendor="phpadsnew">
        <vers num="2.0_beta5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1055" seq="2001-1055" published="2001-07-30" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200323" adv="1">20010730 ARPNuke - 80 kb/s kills a whole subnet</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3113" adv="1">3113</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6924">win-arp-packet-flooding-dos(6924)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_98" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
      <prod name="windows_98se" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1056" seq="2001-1056" published="2001-07-30" modified="2018-09-20" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a "DCC SEND" request to a malicious server which listens on port 6667, which may cause the module to believe that the traffic is a valid request and allow the connection to the port specified in the DCC SEND request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0733.html">20010730 [RAZOR] Linux kernel IP masquerading vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0750.html">20010730 Re: [RAZOR] Linux kernel IP masquerading vulnerability (_actual_ patch)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6923.php">linux-ipmasqirc-bypass-protection(6923)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3117" adv="1">3117</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4" edition="rc1"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13" edition="pre15"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15" edition="pre16"/>
        <vers num="2.2.16" edition="pre5"/>
        <vers num="2.2.16" edition="pre6"/>
        <vers num="2.2.17" edition="pre14"/>
        <vers num="2.2.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1057" seq="2001-1057" published="2001-07-30" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200462" adv="1" patch="1">20010730 a couple minor issues with mathematica license manager</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3120" adv="1">3120</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6926">mathematica-license-dos(6926)</ref>
    </refs>
    <vuln_soft>
      <prod name="mathematica" vendor="wolfram_research">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1058" seq="2001-1058" published="2002-02-13" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200462" adv="1" patch="1">20010730 a couple minor issues with mathematica license manager</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3118" adv="1">3118</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6927">mathematica-license-retrieval(6927)</ref>
    </refs>
    <vuln_soft>
      <prod name="mathematica" vendor="wolfram_research">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1059" seq="2001-1059" published="2001-07-30" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license information.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200455" adv="1">20010730 vmware bug?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3119" adv="1" patch="1">3119</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6925">vmware-obtain-license-info(6925)</ref>
    </refs>
    <vuln_soft>
      <prod name="workstation" vendor="vmware">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1060" seq="2001-1060" published="2001-07-31" modified="2009-04-03" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://freshmeat.net/redir/phpmyadmin/8001/url_changelog/">http://freshmeat.net/redir/phpmyadmin/8001/url_changelog/</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/200596">20010731 New command execution vulnerability in myPhpAdmin</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3121" patch="1">3121</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyadmin" vendor="phpmyadmin">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.2_pre1"/>
        <vers num="2.2_rc1"/>
        <vers num="2.2_rc2"/>
        <vers num="2.2_rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1061" seq="2001-1061" published="2001-08-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/aix/2001-q3/0003.html" adv="1">IY22255</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1062" seq="2001-1062" published="2001-08-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.12/CSSA-2001-SCO.12.txt" adv="1">CSSA-2001-SCO.12</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7034.php">openserver-mana-bo(7034)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="caldera">
        <vers num="5.0.6a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1063" seq="2001-1063" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in uidadmin in Caldera Open Unix 8.0.0 and UnixWare 7 allows local users to gain root privileges via a long -S (scheme) command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.14/CSSA-2001-SCO.14.txt" adv="1">CSSA-2001-SCO.14</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3244" adv="1" patch="1">3244</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7036">unixware-openunix-uidadmin-bo(7036)</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="caldera">
        <vers num="7"/>
      </prod>
      <prod name="openunix" vendor="caldera">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1064" seq="2001-1064" published="2001-08-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml" adv="1" patch="1">20010823 CBOS Web-based Configuration Utility Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3236" adv="1" patch="1">3236</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7025">cisco-cbos-telnet-dos(7025)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7026">cisco-cbos-http-dos(7026)</ref>
    </refs>
    <vuln_soft>
      <prod name="cbos" vendor="cisco">
        <vers num="2.0.1"/>
        <vers num="2.1.0"/>
        <vers num="2.1.0a"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.1a"/>
        <vers num="2.3"/>
        <vers num="2.3.2"/>
        <vers num="2.3.5"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.2ap" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1065" seq="2001-1065" published="2001-08-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml" adv="1" patch="1">20010823 CBOS Web-based Configuration Utility Vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7027">cisco-cbos-web-config(7027)</ref>
    </refs>
    <vuln_soft>
      <prod name="cbos" vendor="cisco">
        <vers num="2.0.1"/>
        <vers num="2.4.2ap" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1066" seq="2001-1066" published="2001-08-31" modified="2018-05-02" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0036.html">20010827 Dangerous temp file creation during installation of Netscape 6.</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99893667921216&amp;w=2">20010827 Dangerous temp file creation during installation of Netscape 6.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3243" adv="1">3243</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7042">netscape-install-tmpfile-symlink(7042)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1067" seq="2001-1067" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0325.html" adv="1">20010822 AOLserver 3.0 vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213041">20010906 AOLserver exploit code</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3230" adv="1" patch="1">3230</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7030">aolserver-long-password-dos(7030)</ref>
    </refs>
    <vuln_soft>
      <prod name="aol_server" vendor="aol">
        <vers num="3.0"/>
        <vers num="3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1068" seq="2001-1068" published="2001-08-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0363.html" adv="1">20010825 qpopper and pam.d</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3242" adv="1" patch="1">3242</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7047">qpopper-pam-auth-error(7047)</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1069" seq="2001-1069" published="2001-08-31" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://lists.debian.org/debian-security/2001/debian-security-200101/msg00085.html" adv="1">http://lists.debian.org/debian-security/2001/debian-security-200101/msg00085.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99849121502399&amp;w=2">20010822 Adobe Acrobat creates world writable ~/AdobeFnt.lst files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3225" adv="1" patch="1">3225</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7024">adobe-acrobat-insecure-permissions(7024)</ref>
    </refs>
    <vuln_soft>
      <prod name="acrobat_reader" vendor="adobe">
        <vers num="4.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1070" seq="2001-1070" published="2001-08-31" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0312.html" adv="1">20010821 Bug in MAS90 Accounting Platform remote access?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3221" adv="1">3221</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7020">mas-telnet-connect-dos(7020)</ref>
    </refs>
    <vuln_soft>
      <prod name="mas_200" vendor="sage_software">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1071" seq="2001-1071" published="2001-10-09" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139491">VU#139491</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/219257" adv="1" patch="1">20011009 Cisco CDP attacks</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/219305" adv="1" patch="1">20011009 Cisco Systems - Vulnerability in CDP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3412" adv="1" patch="1">3412</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7242">cisco-ios-cdp-dos(7242)</ref>
    </refs>
    <vuln_soft>
      <prod name="catos" vendor="cisco">
        <vers num="4.5(1)"/>
      </prod>
      <prod name="ios" vendor="cisco">
        <vers num="11.1"/>
        <vers num="11.2"/>
        <vers num="11.3(11)b"/>
        <vers num="12.0(5.1)xp"/>
        <vers num="12.0(19)"/>
        <vers num="12.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1072" seq="2001-1072" published="2001-08-31" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/02-02-01#security">http://www.apacheweek.com/issues/02-02-01#security</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/203955" adv="1" patch="1">20010812 Are your mod_rewrite rules doing what you expect?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3176" adv="1" patch="1">3176</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8633">apache-rewrite-bypass-directives(8633)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1073" seq="2001-1073" published="2001-08-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Webridge PX Application Suite allows remote attackers to obtain sensitive information via a malformed request that generates a server error message, which includes full pathname or internal IP address information in the variables (1) APPL_PHYSICAL_PATH, (2) PATH_TRANSLATED, and (3) LOCAL_ADDR.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/204725" adv="1">20010815 webridge application suite gives up too much error information on Internal Server Error</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3182" adv="1">3182</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6993">webridge-px-reveal-information(6993)</ref>
    </refs>
    <vuln_soft>
      <prod name="px_application_suite" vendor="webridge">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1074" seq="2001-1074" published="2001-05-28" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Webmin 0.84 and earlier does not properly clear the HTTP_AUTHORIZATION environment variable when the web server is restarted, which makes authentication information available to all CGI programs and allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0262.html" adv="1">20010526 Webmin Doesn't Clean Env (root exploit)</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-019.1.txt" adv="1" patch="1">CSSA-2001-019.1</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-059.php3" patch="1">MDKSA-2001:059</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2795" adv="1" patch="1">2795</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6627">webmin-gain-information(6627)</ref>
    </refs>
    <vuln_soft>
      <prod name="webmin" vendor="webmin">
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.80"/>
        <vers num="0.83"/>
        <vers num="0.84"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1075" seq="2001-1075" published="2001-07-04" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by causing a "POP login by user" string that includes the attacker's IP address to be injected into the maillog log file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0064.html" adv="1">20010703 poprelayd and sendmail relay authentication problem (Cobalt Raq3)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0150.html" adv="1" patch="1">20010709 Re: poprelayd and sendmail relay authentication problem (Cobalt Raq3)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2986" adv="1">2986</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6806">cobalt-poprelayd-mail-relay(6806)</ref>
    </refs>
    <vuln_soft>
      <prod name="cobalt_raq_3i" vendor="sun">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1076" seq="2001-1076" published="2001-07-05" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0076.html" adv="1" patch="1">20010705 Solaris whodo Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2935" adv="1" patch="1">2935</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6802">solaris-whodo-bo(6802)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A34">oval:org.mitre.oval:def:34</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A47">oval:org.mitre.oval:def:47</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1077" seq="2001-1077" published="2001-06-15" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-028-01" adv="1" patch="1">IMNX-2001-70-028-01</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-062" adv="1" patch="1">DSA-062</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-060.php">MDKSA-2001:060</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/191510" adv="1" patch="1">20010615 Rxvt vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2878">2878</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6701">rxvt-ttprintf-bo(6701)</ref>
    </refs>
    <vuln_soft>
      <prod name="rxvt" vendor="rxvt">
        <vers num="2.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1078" seq="2001-1078" published="2001-06-21" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0291.html">20010622 eXtremail Remote Format String ('s)</ref>
      <ref source="CONFIRM" url="http://www.extremail.com/history.htm">http://www.extremail.com/history.htm</ref>
      <ref source="CONFIRM" url="http://www.extremail.com/news.htm">http://www.extremail.com/news.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2908" adv="1" patch="1">2908</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6733">extremail-flog-format-string(6733)</ref>
    </refs>
    <vuln_soft>
      <prod name="extremail" vendor="extremail">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.1"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1079" seq="2001-1079" published="2002-02-13" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/aix/2001-q3/0000.html" adv="1" patch="1">IY19069</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8923">aix-keyfile-world-writable(8923)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="3.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1080" seq="2001-1080" published="2001-06-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2916">2916</ref>
      <ref source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2001.225.1/$file/oar225.txt" adv="1" patch="1">MSS-OAR-E01-2001:225.1</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6734">aix-diagrpt-root-shell(6734)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1081" seq="2001-1081" published="2001-07-06" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html">[fm-news] 20010713 Newsletter for Friday, July 13th 2001</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
      <ref source="CONFIRM" url="http://freshmeat.net/releases/52020/" adv="1">http://freshmeat.net/releases/52020/</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2994" adv="1" patch="1">2994</ref>
    </refs>
    <vuln_soft>
      <prod name="radius" vendor="lucent">
        <vers num="2.1.2"/>
      </prod>
      <prod name="radius" vendor="simon_horms">
        <vers num="2.1_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1082" seq="2001-1082" published="2001-07-13" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://freshmeat.net/releases/52020/" adv="1">http://freshmeat.net/releases/52020/</ref>
    </refs>
    <vuln_soft>
      <prod name="radius" vendor="lucent">
        <vers num="2.1.2"/>
      </prod>
      <prod name="radius" vendor="simon_horms">
        <vers num="2.1_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1083" seq="2001-1083" published="2001-06-26" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-020.0.txt">CSSA-2002-020.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-089">DSA-089</ref>
      <ref source="MISC" url="http://www.icecast.org/index.html">http://www.icecast.org/index.html</ref>
      <ref source="CONFIRM" url="http://www.icecast.org/releases/icecast-1.3.11.tar.gz">http://www.icecast.org/releases/icecast-1.3.11.tar.gz</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-105.html">RHSA-2001:105</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-063.html">RHSA-2002:063</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/193516" adv="1">20010626 Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2933" adv="1" patch="1">2933</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6751">icecast-http-remote-dos(6751)</ref>
    </refs>
    <vuln_soft>
      <prod name="icecast" vendor="icecast">
        <vers num="1.0.0"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8_beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1084" seq="2001-1084" published="2001-07-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Allaire JRun 3.0 and 2.3.3 allows a malicious webmaster to embed Javascript in a request for a .JSP, .shtml, .jsp10, .jrun, or .thtml file that does not exist, which causes the Javascript to be inserted into an error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html">20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/654643">VU#654643</ref>
      <ref source="ALLAIRE" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=21498&amp;Method=Full">MPSB01-06</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2983" adv="1" patch="1">2983</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6793">java-servlet-crosssite-scripting(6793)</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.3"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1085" seq="2001-1085" published="2001-07-05" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195022" adv="1" patch="1">20010705 lmail local root exploit</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2984" adv="1">2984</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6809">lmail-tmpfile-symlink(6809)</ref>
    </refs>
    <vuln_soft>
      <prod name="lmail" vendor="jon_zeeff">
        <vers num="2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1086" seq="2001-1086" published="2001-07-04" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/195008" adv="1">20010705 Re: xdm cookies fast brute force</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194907" adv="1">20010704 xdm cookies fast brute force</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2985" adv="1" patch="1">2985</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6808">xdm-cookie-brute-force(6808)</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3"/>
        <vers num="3.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1087" seq="2001-1087" published="2001-07-05" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195176" adv="1">20010705 RE: Tunnel ports allowed on NetApp NetCaches</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2990" adv="1">2990</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6807">netcache-tunnel-default-configuration(6807)</ref>
    </refs>
    <vuln_soft>
      <prod name="netcache" vendor="network_appliance">
        <vers num="c700"/>
        <vers num="c1100"/>
        <vers num="c3100"/>
        <vers num="c6100"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1088" seq="2001-1088" published="2001-06-05" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.microsoft.com/default.aspx?scid=kb;EN-US;q234241">http://support.microsoft.com/default.aspx?scid=kb;EN-US;q234241</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/188752" adv="1">20010605 SECURITY.NNOV: Outlook Express address book spoofing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2823" adv="1">2823</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6655">outlook-address-book-spoofing(6655)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook" vendor="microsoft">
        <vers num="97"/>
        <vers num="98"/>
        <vers num="2000"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="4.0"/>
        <vers num="4.5"/>
        <vers num="4.27.3110"/>
        <vers num="4.72.2106"/>
        <vers num="4.72.3120.0"/>
        <vers num="4.72.3612"/>
        <vers num="5.0"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1089" seq="2001-1089" published="2001-09-10" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213331" adv="1" patch="1">20010910 RUS-CERT Advisory 2001-09:01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3314" adv="1" patch="1">3314</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7111">postgresql-nss-authentication-modules(7111)</ref>
    </refs>
    <vuln_soft>
      <prod name="nss_postgresql" vendor="alessandro_gardich">
        <vers num="0.6.1"/>
      </prod>
      <prod name="libnss-pgsql" vendor="joerg_wendland">
        <vers num="0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1090" seq="2001-1090" published="2001-09-10" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213331" adv="1" patch="1">20010910 RUS-CERT Advisory 2001-09:01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3315" adv="1">3315</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7111">postgresql-nss-authentication-modules(7111)</ref>
    </refs>
    <vuln_soft>
      <prod name="nss_postgresql" vendor="alessandro_gardich">
        <vers num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1091" seq="2001-1091" published="2001-08-23" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-014.txt.asc">NetBSD-SA2001-014</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7037">bsd-dump-tty-privileges(7037)</ref>
    </refs>
    <vuln_soft>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1092" seq="2001-1092" published="2001-09-10" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/440539">VU#440539</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213238" adv="1">20010910 Digital Unix 4.0x msgchk multiple vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3320" adv="1">3320</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7102">du-msgchk-symlink(7102)</ref>
    </refs>
    <vuln_soft>
      <prod name="tru64" vendor="compaq">
        <vers num="4.0d"/>
        <vers num="4.0e"/>
        <vers num="4.0f"/>
        <vers num="4.0g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1093" seq="2001-1093" published="2001-09-10" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213238" adv="1">20010910 Digital Unix 4.0x msgchk multiple vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3311" adv="1">3311</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7101">du-msgchk-bo(7101)</ref>
    </refs>
    <vuln_soft>
      <prod name="tru64" vendor="compaq">
        <vers num="4.0d"/>
        <vers num="4.0e"/>
        <vers num="4.0f"/>
        <vers num="4.0g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1094" seq="2001-1094" published="2001-09-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213516" adv="1">20010911 NetOP School Admin Vulnerability for Windows 2000 Terminal Services and NT4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3321" adv="1">3321</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7120">netop-school-bypass-authentication(7120)</ref>
    </refs>
    <vuln_soft>
      <prod name="netop_school" vendor="crosstec_corporation">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1095" seq="2001-1095" published="2001-10-09" modified="2016-09-16" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in uuq in AIX 4 could allow local users to execute arbitrary code via a long -r parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/aix/2001-q4/0000.html" adv="1">IY23401</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY24231&amp;apar=only">IY24231</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1096" seq="2001-1096" published="2001-10-09" modified="2013-07-25" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/aix/2001-q4/0000.html" adv="1">IY23402</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1097" seq="2001-1097" published="2001-07-24" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99749327219189&amp;w=2">20010811 Re: UDP packet handling weird behaviour of various operating systems</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/199558" adv="1">20010724 UDP packet handling weird behaviour of various operating systems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3096" adv="1">3096</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6913">cisco-ios-udp-dos(6319)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.0"/>
        <vers num="12.0(1)"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(3)"/>
        <vers num="12.0(4)"/>
        <vers num="12.0(5)"/>
        <vers num="12.0(6)"/>
        <vers num="12.0(7)t"/>
        <vers num="12.1"/>
        <vers num="12.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1098" seq="2001-1098" published="2001-10-10" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0071.html" adv="1" patch="1">20011010 Vulnerability: Cisco PIX Firewall Manager</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/639507" adv="1">VU#639507</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3419">3419</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7265">cisco-pfm-plaintext-password(7265)</ref>
    </refs>
    <vuln_soft>
      <prod name="pix_firewall_manager" vendor="cisco">
        <vers num="4.3(2)g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1099" seq="2001-1099" published="2001-09-07" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212724" adv="1">20010907 Microsoft Exchange + Norton AntiVirus leak local information</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213762" adv="1">20010912 Re: Microsoft Exchange + Norton AntiVirus leak local information</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3305" adv="1">3305</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7093">nav-exchange-reveal-information(7093)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
      <prod name="norton_antivirus" vendor="symantec">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1100" seq="2001-1100" published="2001-10-07" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218921" adv="1" patch="1">20011007 Bug found at W3Mail Webmail</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3673" adv="1">3673</ref>
      <ref source="CONFIRM" url="http://www.w3mail.org/ChangeLog">http://www.w3mail.org/ChangeLog</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7230">w3mail-metacharacters-command-execution(7230)</ref>
    </refs>
    <vuln_soft>
      <prod name="w3mail" vendor="spencer_miles">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1101" seq="2001-1101" published="2001-09-08" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)">
    <desc>
      <descript source="cve">The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212826" adv="1" patch="1">20010908 Bug in remote GUI access in CheckPoint Firewall</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3303" adv="1">3303</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7095">fw1-log-file-overwrite(7095)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1102" seq="2001-1102" published="2001-09-08" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212824" adv="1" patch="1">20010908 Bug in compile portion for older versions of CheckPoint Firewalls</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3300" adv="1" patch="1">3300</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7094">fw1-tmp-file-symlink(7094)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.1" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1103" seq="2001-1103" published="2001-03-03" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/320944" adv="1" patch="1">VU#320944</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7119">ftp-voyager-embedded-script-execution(7119)</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_voyager" vendor="rhinosoft">
        <vers num="8.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1104" seq="2001-1104" published="2001-07-25" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/199632" adv="1">20010725 Weak TCP Sequence Numbers in Sonicwall SOHO Firewall</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3098" adv="1">3098</ref>
    </refs>
    <vuln_soft>
      <prod name="soho" vendor="sonicwall">
        <vers num="4.0.0"/>
        <vers num="5.0.0"/>
        <vers num="5.1.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1105" seq="2001-1105" published="2001-09-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-141.shtml" adv="1" patch="1">L-141</ref>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/SSL-J-pub.html">20010912 Vulnerable SSL Implementation in iCDN</ref>
      <ref source="CONFIRM" url="http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL-J_3.x.SecurityBulletin.html">http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL-J_3.x.SecurityBulletin.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3329" adv="1" patch="1">3329</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7112">bsafe-ssl-bypass-authentication(7112)</ref>
    </refs>
    <vuln_soft>
      <prod name="icdn" vendor="cisco">
        <vers num="2.0"/>
      </prod>
      <prod name="bsafe_ssl-j_sdk" vendor="rsa">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1106" seq="2001-1106" published="2001-07-25" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/199418" adv="1">20010725 Sambar Server password decryption</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3095" adv="1" patch="1">3095</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6909">sambar-insecure-passwords(6909)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="4.1"/>
        <vers num="4.2.1_production"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="5.0" edition="beta1"/>
        <vers num="5.0" edition="beta2"/>
        <vers num="5.0" edition="beta3"/>
        <vers num="5.0" edition="beta4"/>
        <vers num="5.0" edition="beta5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1107" seq="2001-1107" published="2001-07-26" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0606.html" adv="1">20010726 Snapstream PVS vulnerability</ref>
      <ref source="CONFIRM" url="http://discuss.snapstream.com/ubb/Forum1/HTML/000216.html">http://discuss.snapstream.com/ubb/Forum1/HTML/000216.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3101" adv="1">3101</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6917">snapstream-dot-directory-traversal(6917)</ref>
    </refs>
    <vuln_soft>
      <prod name="pvs" vendor="snapstream">
        <vers num="1.2a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1108" seq="2001-1108" published="2001-07-26" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0606.html" adv="1">20010726 Snapstream PVS vulnerability</ref>
      <ref source="CONFIRM" url="http://discuss.snapstream.com/ubb/Forum1/HTML/000216.html">http://discuss.snapstream.com/ubb/Forum1/HTML/000216.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3100" adv="1">3100</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6917">snapstream-dot-directory-traversal(6917)</ref>
    </refs>
    <vuln_soft>
      <prod name="pvs" vendor="snapstream">
        <vers num="1.2a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1109" seq="2001-1109" published="2001-09-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.eftp.org/releasehistory.html">http://www.eftp.org/releasehistory.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213647" adv="1">20010912 EFTP Version 2.0.7.337 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3331" adv="1">3331</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3333" adv="1">3333</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7113">eftp-list-directory-traversal(7113)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7114">eftp-quote-reveal-information(7114)</ref>
    </refs>
    <vuln_soft>
      <prod name="eftp" vendor="khamil_landross_and_zack_jones">
        <vers num="2.0.7.337"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1110" seq="2001-1110" published="2001-09-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213647" adv="1">20010912 EFTP Version 2.0.7.337 vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod name="eftp" vendor="khamil_landross_and_zack_jones">
        <vers num="2.0.7.337"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1111" seq="2001-1111" published="2001-09-12" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213647" adv="1">20010912 EFTP Version 2.0.7.337 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3332" adv="1">3332</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7116">eftp-plaintext-password(7116)</ref>
    </refs>
    <vuln_soft>
      <prod name="eftp" vendor="khamil_landross_and_zack_jones">
        <vers num="2.0.7.337"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1112" seq="2001-1112" published="2001-09-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/213647" adv="1">20010912 EFTP Version 2.0.7.337 vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3330" adv="1">3330</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7115">eftp-lnk-bo(7115)</ref>
    </refs>
    <vuln_soft>
      <prod name="eftp" vendor="khamil_landross_and_zack_jones">
        <vers num="2.0.7.337"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1113" seq="2001-1113" published="2001-08-13" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.trolltech.com/freebies/ftpd/troll-ftpd-1.27.tar.gz">ftp://ftp.trolltech.com/freebies/ftpd/troll-ftpd-1.27.tar.gz</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/203874" adv="1" patch="1">20010813 Local exploit for TrollFTPD-1.26</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3174" adv="1" patch="1">3174</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6974">trollftpd-long-path-bo(6974)</ref>
    </refs>
    <vuln_soft>
      <prod name="trollftpd" vendor="trolltech">
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1114" seq="2001-1114" published="2001-08-13" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/204094" adv="1">20010813 NetCode NC Book 0.2b remote command execution vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3178" adv="1">3178</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6986">netcode-book-pipes-command(6986)</ref>
    </refs>
    <vuln_soft>
      <prod name="nc_book" vendor="netcode">
        <vers num="0.2b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1115" seq="2001-1115" published="2001-08-13" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/204053" adv="1">20010813 SIX-webboard 2.01 "show files" vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3175" adv="1">3175</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6975">sixwebboard-dot-directory-traversal(6975)</ref>
    </refs>
    <vuln_soft>
      <prod name="six-webboard" vendor="sixhead">
        <vers num="2.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1116" seq="2001-1116" published="2001-08-02" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Identix BioLogon 2.03 and earlier does not lock secondary displays on a multi-monitor system running Windows 98 or ME, which allows an attacker with physical access to the system to bypass authentication through a secondary display.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://ntbugtraq.ntadvice.com/default.asp?pid=36&amp;sid=1&amp;A2=IND0108&amp;L=NTBUGTRAQ&amp;F=P&amp;S=&amp;P=71" adv="1">20010802 Identix BioLogon Client security bug</ref>
      <ref source="NTBUGTRAQ" url="http://ntbugtraq.ntadvice.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0108&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=724">20010808 Response to Identix BioLogon Client security bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3140" adv="1">3140</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6948">identix-biologon-auth-bypass(6948)</ref>
    </refs>
    <vuln_soft>
      <prod name="biologon" vendor="identix">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1117" seq="2001-1117" published="2001-08-10" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.linksys.com/pub/befsr41/befsr-fw1402.zip">ftp://ftp.linksys.com/pub/befsr41/befsr-fw1402.zip</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201390">20010802 Advisory Update: Design Flaw in Linksys EtherFast 4-Port</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/203302" adv="1" patch="1">20010810 Linksys router security fix</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3141" adv="1" patch="1">3141</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6949">linksys-etherfast-reveal-passwords(6949)</ref>
    </refs>
    <vuln_soft>
      <prod name="befsr41" vendor="linksys">
        <vers num="1.35"/>
        <vers num="1.36"/>
        <vers num="1.37"/>
        <vers num="1.38.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1118" seq="2001-1118" published="2001-08-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://download.roxen.com/2.0/patch/security-notice.html">http://download.roxen.com/2.0/patch/security-notice.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201476" adv="1" patch="1">20010802 Roxen security alert: URL decoding vulnerable</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201499">20010802 FW: Security alert: Remote user can access any file</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3145" adv="1" patch="1">3145</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6937">roxen-urlrectifier-retrieve-files(6937)</ref>
    </refs>
    <vuln_soft>
      <prod name="roxen_webserver" vendor="roxen">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1119" seq="2001-1119" published="2001-08-03" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/105347" adv="1" patch="1">VU#105347</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_025_xmcd_txt.html">SuSE-SA:2001:025</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3148" adv="1" patch="1">3148</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6941">xmcd-cda-symlink(6941)</ref>
    </refs>
    <vuln_soft>
      <prod name="xmcd" vendor="ti_kan">
        <vers num="2.6.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1120" seq="2001-1120" published="2001-07-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.allaire.com/handlers/index.cfm?id=21566">http://www.allaire.com/handlers/index.cfm?id=21566</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/135531">VU#135531</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/196452" adv="1">20010712 New Cold Fusion vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3018" adv="1" patch="1">3018</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6839">coldfusion-unauthorized-file-access(6839)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion_server" vendor="allaire">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.5"/>
        <vers num="4.5.1"/>
        <vers num="4.5.1_sp1"/>
        <vers num="4.5.1_sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1121" seq="2001-1121" published="2001-07-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-2001-1084.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs/>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.3"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1122" seq="2001-1122" published="2001-08-03" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201722" adv="1" patch="1">20010803 REPOST: A damaging local DoS in WinNT SP6a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3144" adv="1">3144</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6943">winnt-nt4all-dos(6943)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1123" seq="2001-1123" published="2001-10-01" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/782155">VU#782155</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3585" adv="1" patch="1">HPSBUX0110-170</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3723">HPSBUX0112-177</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3399" adv="1" patch="1">3399</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7222">openview-nmm-gain-privileges(7222)</ref>
    </refs>
    <vuln_soft>
      <prod name="openview_network_node_manager" vendor="hp">
        <vers num="5.01"/>
        <vers num="6.1"/>
        <vers num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1124" seq="2001-1124" published="2001-10-01" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-003.shtml">M-003</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3586" adv="1">HPSBUX0110-169</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3400" adv="1" patch="1">3400</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7221">hp-rpcbind-dos(7221)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5683">oval:org.mitre.oval:def:5683</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1125" seq="2001-1125" published="2001-10-05" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.sarc.com/avcenter/security/Content/2001.10.05.html">http://www.sarc.com/avcenter/security/Content/2001.10.05.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218717" adv="1" patch="1">20011005 Symantec LiveUpdate attacks</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3403" adv="1" patch="1">3403</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7235">liveupdate-host-verification(7235)</ref>
    </refs>
    <vuln_soft>
      <prod name="liveupdate" vendor="symantec">
        <vers num="1.4"/>
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1126" seq="2001-1126" published="2001-10-05" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.sarc.com/avcenter/security/Content/2001.10.05.html">http://www.sarc.com/avcenter/security/Content/2001.10.05.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218717" adv="1" patch="1">20011005 Symantec LiveUpdate attacks</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3413" adv="1">3413</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7235">liveupdate-host-verification(7235)</ref>
    </refs>
    <vuln_soft>
      <prod name="liveupdate" vendor="symantec">
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1127" seq="2001-1127" published="2001-10-05" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4) orarx, (5) sqlcpp, (6) _probrkr, (7) _sqlschema and (8) _sqldump.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218833" adv="1">20011005 Progress Database vulnerabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3404" adv="1" patch="1">3404</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7236">progress-strcpy-bo(7236)</ref>
    </refs>
    <vuln_soft>
      <prod name="progress" vendor="progress">
        <vers num="8.3d"/>
        <vers num="9.1c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1128" seq="2001-1128" published="2001-10-08" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP environment variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/219174" adv="1">20011008 Progress TERM (protermcap) overflows and PROMSGS overflows</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3414" adv="1" patch="1">3414</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7264">progress-protermcap-bo(7264)</ref>
    </refs>
    <vuln_soft>
      <prod name="progress" vendor="progress">
        <vers num="8.3d"/>
        <vers num="9.1c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1129" seq="2001-1129" published="2001-11-02" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerabilities in (1) _probuild, (2) _dbutil, (3) _mprosrv, (4) _mprshut, (5) _proapsv, (6) _progres, (7) _proutil, (8) _rfutil and (9) prolib in Progress database 9.1C allows a local user to execute arbitrary code via format string specifiers in the file used by the PROMSGS environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/224395" adv="1">20011102 Progres Databse PROMSGS Format strings issue.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3502" adv="1" patch="1">3502</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7457">progress-promsgs-format-string(7457)</ref>
    </refs>
    <vuln_soft>
      <prod name="progress" vendor="progress">
        <vers num="9.1c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1130" seq="2001-1130" published="2001-08-02" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using a .. in the HTTP referer (from the HTTP_REFERER variable) to point to the directory that contains the keylist.txt file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_027_sdb_txt.html">SuSE-SA:2001:027</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201216" adv="1" patch="1">20010802 suse: sdbsearch.cgi vulnerability</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7003">sdbsearch-cgi-command-execution(7003)</ref>
    </refs>
    <vuln_soft>
      <prod name="suse_linux" vendor="suse">
        <vers num="6.0"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0"/>
        <vers num="7.1"/>
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1131" seq="2001-1131" published="2001-08-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5RP0L0055O.html" adv="1">http://www.securiteam.com/windowsntfocus/5RP0L0055O.html</ref>
    </refs>
    <vuln_soft>
      <prod name="slimftpd" vendor="whitsoft_development">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1132" seq="2001-1132" published="2001-09-05" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000420">CLA-2001:420</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7091">mailman-blank-passwords(7091)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailman" vendor="gnu">
        <vers num="2.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1133" seq="2001-1133" published="2001-08-21" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7023.php" adv="1">bsd-kernel-dos(7023)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/209192" adv="1">20010821 BSDi (3.0/3.1) reboot machine code as any user (non-specific)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3220" adv="1">3220</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1134" seq="2001-1134" published="2001-08-09" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6976.php" adv="1" patch="1">xerox-docuprint-dos(6976)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/198381">20010720 Re: Two birds with one worm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/203025">20010809 Xerox N40 printers and Code Red worm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3170">3170</ref>
    </refs>
    <vuln_soft>
      <prod name="docuprint_n40" vendor="xerox">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1135" seq="2001-1135" published="2001-08-14" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/203022">20010809 ZyXEL Prestige 642R: Exposed Admin Services on WAN with Default Password</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/203592">20010810 Re: ZyXEL Prestige 642R: Exposed Admin Services on WAN with Default Password</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/204439" adv="1">20010814 Fwd: ZyXEL Prestige 642 Router Administration Interface Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/214971" adv="1">20010918 SECURITY RISK: ZyXEL ADSL Router 642R - WAN filter bypass from internal network</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3346" adv="1">3346</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7146">prestige-wan-bypass-filter(7146)</ref>
    </refs>
    <vuln_soft>
      <prod name="prestige" vendor="zyxel">
        <vers num="642r"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1136" seq="2001-1136" published="2001-09-13" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q3/0063.html" adv="1" patch="1">HPSBUX0109-166</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-143.shtml" adv="1" patch="1">L-143</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3338">3338</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7124">hp-virtualvault-libsecurity-dos(7124)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1137" seq="2001-1137" published="2001-09-06" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram fragments.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212532" adv="1" patch="1">20010906 Malformed Fragmented Packets DoS Dlink Firewall/Routers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3306">3306</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7090">dlink-fragmented-packet-dos(7090)</ref>
    </refs>
    <vuln_soft>
      <prod name="dl-704" vendor="d-link">
        <vers num="v2.56b5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1138" seq="2001-1138" published="2001-09-07" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212679" adv="1">20010907  *** Security Advisory *** Power UP HTML</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3304" adv="1">3304</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7092">powerup-rcgi-directory-traversal(7092)</ref>
    </refs>
    <vuln_soft>
      <prod name="power_up_html" vendor="randy_parker">
        <vers num="0.8033_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1139" seq="2001-1139" published="2001-08-22" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7015.php" adv="1" patch="1">winwrapper-dot-directory-traversal(7015)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/209414" adv="1" patch="1">20010822 [SNS Advisory No.39] WinWrapper Professional 2.0 Remote Arbitrary File Disclosure Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3219" adv="1" patch="1">3219</ref>
      <ref source="MISC" url="http://www.tsc.ant.co.jp/products/download.htm">http://www.tsc.ant.co.jp/products/download.htm</ref>
    </refs>
    <vuln_soft>
      <prod name="winwrapper_professional" vendor="ascii_nt">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1140" seq="2001-1140" published="2001-08-22" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/209545" adv="1">20010822 -- [ iSecureLabs BadBlue v1.02 beta for Windows 98, ME and 2000 Advisory ] --</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3222" adv="1">3222</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7021">badblue-file-source-disclosure(7021)</ref>
    </refs>
    <vuln_soft>
      <prod name="badblue" vendor="working_resources_inc.">
        <vers num="1.02_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1141" seq="2001-1141" published="2001-07-10" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predict future pseudo-random numbers.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-013.txt.asc">NetBSD-SA2001-013</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000418">CLA-2001:418</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-065.php3?dis=8.0">MDKSA-2001:065</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1483.html">ESA-20010709-01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-051.html" adv="1" patch="1">RHSA-2001:051</ref>
      <ref source="FREEBSD" url="http://www.securityfocus.com/advisories/3475">FreeBSD-SA-01:51</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195829" adv="1" patch="1">20010710 OpenSSL Security Advisory: PRNG weakness in versions up to 0.9.6a</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3004" adv="1" patch="1">3004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6823">openssl-prng-brute-force(6823)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssl" vendor="openssl">
        <vers num="0.9.1c"/>
        <vers num="0.9.2b"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.6a"/>
      </prod>
      <prod name="ssleay" vendor="ssleay">
        <vers num="0.8.1"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1142" seq="2001-1142" published="2001-07-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6848.php" adv="1">argosoft-ftp-weak-encryption(6848)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/196968" adv="1">20010712 ArGoSoft FTP Server 1.2.2.2 Weak password encryption</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3029" adv="1">3029</ref>
    </refs>
    <vuln_soft>
      <prod name="ftp_server" vendor="argosoft">
        <vers num="1.2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1143" seq="2001-1143" published="2001-07-11" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6832.php" adv="1">ibm-db2-ccs-dos(6832)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6833.php" adv="1">ibm-db2-jds-dos(6833)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/196140" adv="1">20010711 IBM Windows DB2 DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3010" adv="1">3010</ref>
    </refs>
    <vuln_soft>
      <prod name="db2_universal_database" vendor="ibm">
        <vers num="7.0" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1144" seq="2001-1144" published="2001-07-11" modified="2013-08-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in McAfee ASaP VirusScan agent 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6834.php" adv="1">mcafee-mycio-directory-traversal(6834)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/190267" adv="1">VU#190267</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0107&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=1558">20010716 McAfee ASaP Virusscan - MyCIO HTTP Server Directory Traversal Vul nerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/196272" adv="1">20010711 McAfee ASaP Virusscan - myCIO HTTP Server Directory Traversal Vulnerabilty</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3020" adv="1">3020</ref>
    </refs>
    <vuln_soft>
      <prod name="asap_virusscan" vendor="mcafee">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1145" seq="2001-1145" published="2001-08-17" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:40.fts.v1.1.asc">FreeBSD-SA-01:40</ref>
      <ref source="NETBSD" url="http://archives.neohapsis.com/archives/netbsd/2001-q3/0204.html" adv="1" patch="1">NetBSD-SA2001-016</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8715.php">bsd-fts-race-condition(8715)</ref>
      <ref source="OPENBSD" url="http://www.openbsd.org/errata28.html" patch="1">20010530 029: SECURITY FIX: May 30, 2001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3205">3205</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.3"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1146" seq="2001-1146" published="2001-07-11" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">AllCommerce with debugging enabled in EnGarde Secure Linux 1.0.1 creates temporary files with predictable names, which allows local users to modify files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1492.html" adv="1" patch="1">ESA-20010711-01</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3016">3016</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6830">allcommerce-temp-symlink(6830)</ref>
    </refs>
    <vuln_soft>
      <prod name="allcommerce" vendor="lee_herron">
        <vers num="1.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1147" seq="2001-1147" published="2001-10-08" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-009.shtml">M-009</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7266.php" adv="1" patch="1">utillinux-pamlimits-gain-privileges(7266)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-084.php3">MDKSA-2001:084</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_034_shadow_txt.html">SuSE-SA:2001:034</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-132.html">RHSA-2001:132</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/219175" adv="1">20011008 pam_limits.so Bug!!</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3415" adv="1" patch="1">3415</ref>
    </refs>
    <vuln_soft>
      <prod name="util-linux" vendor="andries_brouwer">
        <vers num="2.10s"/>
        <vers num="2.11f"/>
        <vers num="2.11h"/>
        <vers num="2.11i"/>
        <vers num="2.11k"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1148" seq="2001-1148" published="2001-06-13" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.securityfocus.com/archive/1/219966" adv="1" patch="1">CSSA-2001-SCO.25</ref>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/191216" adv="1">20010613 SCO atcronsh auditsh termsh overflows</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7281">openserver-scoadmin-sysadm-bo(7281)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1149" seq="2001-1149" published="2001-08-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/209328" adv="1">20010821 RE: Bug report -- Incident number 240649</ref>
    </refs>
    <vuln_soft>
      <prod name="panda_antivirus_platinum" vendor="panda">
        <vers num="6.23.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1150" seq="2001-1150" published="2001-08-22" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Vulnerability in cgiWebupdate.exe in Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.5.2 through 3.5.4 allows remote attackers to read arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7014.php" adv="1" patch="1">officescan-iuser-read-files(7014)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/209375" adv="1" patch="1">20010822 [SNS Advisory No.38] Trend Micro Virus Buster (Ver.3.5x) Remote</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/210087">20010824 [SNS Advisory No.40] TrendMicro OfficeScan Corp Edition ver.3.54 Remote read file of IUSER authority Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3216" adv="1" patch="1">3216</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trend_micro">
        <vers num="corporate_3.5"/>
        <vers num="corporate_3.54"/>
      </prod>
      <prod name="virus_buster" vendor="trend_micro">
        <vers num="corporate_3.52"/>
        <vers num="corporate_3.53"/>
        <vers num="corporate_3.54"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1151" seq="2001-1151" published="2001-10-15" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted password.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/220666" adv="1" patch="1">20011015 [SNS Advisory No.44] Trend Micro OfficeScan Corporate Edition(Virus Buster Corporate Edition)</ref>
      <ref source="MISC" url="http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=318">http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=318</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7286">officescan-config-file-access(7286)</ref>
    </refs>
    <vuln_soft>
      <prod name="officescan" vendor="trend_micro">
        <vers num="corporate_3.53"/>
      </prod>
      <prod name="virus_buster" vendor="trend_micro">
        <vers num="corporate_3.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1152" seq="2001-1152" published="2001-09-05" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.mimesweeper.com/support/technotes/notes/1043.asp" adv="1">http://www.mimesweeper.com/support/technotes/notes/1043.asp</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212283" adv="1">20010905 Various problems in Baltimore WebSweeper URL filtering</ref>
      <ref source="BID" url="http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&amp;id=3296" adv="1">3296</ref>
    </refs>
    <vuln_soft>
      <prod name="websweeper" vendor="baltimore_technologies">
        <vers num="4.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1153" seq="2001-1153" published="2001-08-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">lpsystem in OpenUnix 8.0.0 allows local users to cause a denial of service and possibly execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0391.html" adv="1" patch="1">CSSA-2001-SCO.15</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7041.php" adv="1" patch="1">openunix-lpsystem-bo(7041)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3248">3248</ref>
    </refs>
    <vuln_soft>
      <prod name="openunix" vendor="caldera">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1154" seq="2001-1154" published="2001-08-30" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/211056" adv="1">20010830 Possible Denial of Service with PHP and Cyrus IMAP on BSDi 4.2</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3260" adv="1">3260</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7053">cyrus-imap-php-dos(7053)</ref>
    </refs>
    <vuln_soft>
      <prod name="cyrus_imap_server" vendor="carnegie_mellon_university">
        <vers num="1.6.24"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
      </prod>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1155" seq="2001-1155" published="2001-08-23" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:56.tcp_wrappers.asc" adv="1" patch="1">FreeBSD-SA-01:56</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.1.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1156" seq="2001-1156" published="2001-10-08" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://membres.lycos.fr/typsoft/eng/history.html">http://membres.lycos.fr/typsoft/eng/history.html</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7247.php" adv="1">typsoft-ftp-retr-stor-dos(7247)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/219167" adv="1">20011008 [ASGUARD-LABS] TYPSoft FTP Server v0.95 STOR/RETR Denial of Service Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3409" adv="1">3409</ref>
    </refs>
    <vuln_soft>
      <prod name="typsoft_ftp_server" vendor="typsoft">
        <vers num="0.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1157" seq="2001-1157" published="2001-08-12" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading &lt; and one or more characters before the SCRIPT tag, or (2) tags using Unicode.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/203821" adv="1">20010812 Various problems in Baltimore's WEBSweeper Script filter ing</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3172" adv="1">3172</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3173" adv="1">3173</ref>
    </refs>
    <vuln_soft>
      <prod name="websweeper" vendor="baltimore_technologies">
        <vers num="4.0"/>
        <vers num="4.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1158" seq="2001-1158" published="2001-07-09" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0128.html" adv="1" patch="1">20010709 Check Point FireWall-1 RDP Bypass Vulnerability</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-109.shtml">L-109</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/cgi-bin/archive.pl?id=1&amp;start=2002-03-11&amp;end=2002-03-17&amp;mid=195647&amp;threads=1">20010709 Check Point response to RDP Bypass</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-17.html">CA-2001-17</ref>
      <ref source="CHECKPOINT" url="http://www.checkpoint.com/techsupport/alerts/rdp.html">20010712 RDP Bypass workaround for VPN-1/FireWall 4.1 SPx</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/310295">VU#310295</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2952" adv="1" patch="1">2952</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6815">fw1-rdp-bypass(6815)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1_build_41439"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1159" seq="2001-1159" published="2001-07-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0029.html" adv="1" patch="1">20010702 (SRADV00010) Remote command execution vulnerabilities in SquirrelMail</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6775.php" adv="1" patch="1">squirrelmail-loadprefs-execute-code(6775)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2968" adv="1" patch="1">2968</ref>
      <ref source="MISC" url="http://www.squirrelmail.org/changelog.php">http://www.squirrelmail.org/changelog.php</ref>
    </refs>
    <vuln_soft>
      <prod name="squirrelmail" vendor="squirrelmail">
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1160" seq="2001-1160" published="2001-06-18" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/191829" adv="1" patch="1">20010618 udirectory from Microburst Technologies remote command execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2884" adv="1">2884</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6706">udirectory-remote-command-execution(6706)</ref>
    </refs>
    <vuln_soft>
      <prod name="udirectory" vendor="microburst">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1161" seq="2001-1161" published="2001-07-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6789.php" adv="1" patch="1">lotus-domino-css(6789)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/642239" adv="1">VU#642239</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194465" adv="1">20010702 Lotus Domino Server Cross-Site Scripting Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194609">20010702 Re: Lotus Domino Server Cross-Site Scripting Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2962" adv="1">2962</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_r5_server" vendor="lotus">
        <vers num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1162" seq="2001-1162" published="2001-06-23" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011002-01-P">20011002-01-P</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-105.shtml">L-105</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000405">CLA-2001:405</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-027-01">IMNX-2001-70-027-01</ref>
      <ref source="CONFIRM" url="http://us1.samba.org/samba/whatsnew/macroexploit.html">http://us1.samba.org/samba/whatsnew/macroexploit.html</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-024.0.txt">CSSA-2001-024.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-065">DSA-065</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-062.php3">MDKSA-2001-062</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-086.html">RHSA-2001:086</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3423">HPSBUX0107-157</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/193027" adv="1" patch="1">20010623 smbd remote file creation vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2928" adv="1" patch="1">2928</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6731">samba-netbios-file-creation(6731)</ref>
    </refs>
    <vuln_soft>
      <prod name="cifs-9000_server" vendor="hp">
        <vers num="a.01.05"/>
        <vers num="a.01.06"/>
      </prod>
      <prod name="samba" vendor="samba">
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1163" seq="2001-1163" published="2001-06-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2885" adv="1">2885</ref>
    </refs>
    <vuln_soft>
      <prod name="netsql" vendor="munica">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1164" seq="2001-1164" published="2001-06-27" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/unixware/CSSA-2001-SCO.4/CSSA-2001-SCO.4.txt" adv="1" patch="1">CSSA-2001-SCO.4</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="caldera">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1165" seq="2001-1165" published="2002-04-01" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7018.php" adv="1">fileguard-weak-password-encryption(7018)</ref>
      <ref source="MISC" url="http://www.securemac.com/fileguard.php#disengage">http://www.securemac.com/fileguard.php#disengage</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3213" adv="1">3213</ref>
    </refs>
    <vuln_soft>
      <prod name="diskguard" vendor="intego">
        <vers num="2.0"/>
      </prod>
      <prod name="fileguard" vendor="intego">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1166" seq="2001-1166" published="2001-08-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:55.procfs.asc">FreeBSD-SA-01:55</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7017.php" adv="1" patch="1">linprocfs-process-memory-leak(7017)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3217" adv="1" patch="1">3217</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1167" seq="2001-1167" published="2001-08-28" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2001-0976.  Reason: This candidate is a duplicate of CVE-2001-0976.  Notes: CVE-2001-0976 should be used instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-1168" seq="2001-1168" published="2001-08-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0408.html" adv="1">20010829 eRisk Security Advisory:  PhpMyExplorer vulnerable to directory traversal.</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0418.html" adv="1">20010830 Re: eRisk Security Advisory:  PhpMyExplorer vulnerable to directory traversal.</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmyexplorer_classic" vendor="phpmyexplorer">
        <vers num="1.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.2"/>
      </prod>
      <prod name="phpmyexplorer_multiuser" vendor="phpmyexplorer">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1169" seq="2001-1169" published="2001-09-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0441.html" adv="1" patch="1">20010902 S/Key keyinit(1) authentication (lack thereof) + sudo(1)</ref>
    </refs>
    <vuln_soft>
      <prod name="s_key" vendor="bell_communications_research">
        <vers num="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1170" seq="2001-1170" published="2001-09-29" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and PIN numbers.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html">20010929 Vulnerability in Amtote International  homebet self service wagering system.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3370" adv="1" patch="1">3370</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7186">homebet-view-logfile(7186)</ref>
    </refs>
    <vuln_soft>
      <prod name="homebet" vendor="amtote_international">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1171" seq="2001-1171" published="2002-04-01" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0046.html" adv="1" patch="1">20010907 Bug in compile portion for older versions of CheckPoint Firewalls</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="3.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1172" seq="2001-1172" published="2001-07-19" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbolic link to that file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0357.html" adv="1" patch="1">20010719 [SNS Advisory No.37] HTTProtect allows attackers to change the protected file using a symlink</ref>
      <ref source="CONFIRM" url="http://www.omnisecure.com/security-alert.html">http://www.omnisecure.com/security-alert.html</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6880">httprotect-protected-file-symlink(6880)</ref>
    </refs>
    <vuln_soft>
      <prod name="httprotect" vendor="omnisecure">
        <vers num="1.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1173" seq="2001-1173" published="2001-07-26" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://innominate.org/oku/masqmail/ChangeLog-stable" adv="1">ftp://innominate.org/oku/masqmail/ChangeLog-stable</ref>
    </refs>
    <vuln_soft>
      <prod name="masqmail" vendor="masqmail">
        <vers num="0.0.0"/>
        <vers num="0.0.1"/>
        <vers num="0.0.2"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.7"/>
        <vers num="0.0.8"/>
        <vers num="0.0.9"/>
        <vers num="0.0.10"/>
        <vers num="0.0.11"/>
        <vers num="0.0.12"/>
        <vers num="0.0.13"/>
        <vers num="0.1.0"/>
        <vers num="0.1.1"/>
        <vers num="0.1.2"/>
        <vers num="0.1.3"/>
        <vers num="0.1.4"/>
        <vers num="0.1.5"/>
        <vers num="0.1.6"/>
        <vers num="0.1.7"/>
        <vers num="0.1.8"/>
        <vers num="0.1.9"/>
        <vers num="0.1.10"/>
        <vers num="0.1.11"/>
        <vers num="0.1.12"/>
        <vers num="0.1.13"/>
        <vers num="0.1.14"/>
        <vers num="0.1.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1174" seq="2001-1174" published="2002-04-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Elm 2.5.5 and earlier allows remote attackers to execute arbitrary code via a long Message-ID header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-067.php">MDKSA-2001:067</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-091.html" patch="1">RHSA-2001:091</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6852">elm-messageid-bo(6852)</ref>
    </refs>
    <vuln_soft>
      <prod name="elm" vendor="elm_development_group">
        <vers num="2.5.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1175" seq="2001-1175" published="2002-04-01" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-095.html" adv="1" patch="1">RHSA-2001:095</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-132.html">RHSA-2001:132</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3036" adv="1" patch="1">3036</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6851">vipw-world-readable-files(6851)</ref>
    </refs>
    <vuln_soft>
      <prod name="util-linux" vendor="andries_brouwer">
        <vers num="2.10s"/>
        <vers num="2.11d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1176" seq="2001-1176" published="2001-07-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0209.html" adv="1" patch="1">20010712 VPN-1/FireWall-1 Format Strings Vulnerability</ref>
      <ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/format_strings.html">http://www.checkpoint.com/techsupport/alerts/format_strings.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3021" adv="1" patch="1">3021</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6849">fw1-management-format-string(6849)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
      </prod>
      <prod name="provider-1" vendor="checkpoint">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
      </prod>
      <prod name="vpn-1" vendor="checkpoint">
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1177" seq="2001-1177" published="2001-07-17" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0284.html" adv="1" patch="1">20010717 Samsung ML-85G Printer Linux Helper/Driver Binary Exploit (Mandrake: ghostscript package)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3008" adv="1">3008</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6845">samsung-printer-temp-symlink(6845)</ref>
    </refs>
    <vuln_soft>
      <prod name="ml-85g_gdi_printer_driver" vendor="samsung">
        <vers num=""/>
      </prod>
      <prod name="ml-85p_printer_driver" vendor="samsung">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1178" seq="2001-1178" published="2001-07-11" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0234.html" adv="1">20010711 suid xman 3.1.6 overflows</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3030" adv="1">3030</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6853">xfree86-xman-manpath-bo(6853)</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1179" seq="2001-1179" published="2001-07-17" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197498">20010717 xman (suid) exploit, made easier.</ref>
    </refs>
    <vuln_soft>
      <prod name="x11r6" vendor="xfree86_project">
        <vers num="3.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1180" seq="2001-1180" published="2001-07-10" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:42.signal.v1.1.asc">FreeBSD-SA-01:42</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0179.html" adv="1" patch="1">20010710 FreeBSD 4.3 local root, yet Linux and *BSD much better than Windows</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-111.shtml">L-111</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/943633" adv="1" patch="1">VU#943633</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3007" adv="1" patch="1">3007</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6829">bsd-rfork-signal-handlers(6829)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1181" seq="2001-1181" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q3/0013.html" adv="1" patch="1">HPSBUX0107-159</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-115.shtml" adv="1" patch="1">L-115</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6861">hpux-dlkm-gain-privileges(6861)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5479">oval:org.mitre.oval:def:5479</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1182" seq="2001-1182" published="2001-07-17" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q3/0014.html" adv="1" patch="1">HPSBUX0107-160</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5657">oval:org.mitre.oval:def:5657</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.20"/>
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1183" seq="2001-1183" published="2001-07-12" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/PPTP-vulnerability-pub.html" adv="1" patch="1">20010712 Cisco IOS PPTP Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/656315" adv="1" patch="1">VU#656315</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3022" adv="1" patch="1">3022</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6835">cisco-ios-pptp-dos(6835)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.1e"/>
        <vers num="12.1ez"/>
        <vers num="12.1t"/>
        <vers num="12.1ya"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.2"/>
        <vers num="12.2t"/>
        <vers num="12.2xa"/>
        <vers num="12.2xd"/>
        <vers num="12.2xe"/>
        <vers num="12.2xh"/>
        <vers num="12.2xq"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1184" seq="2001-1184" published="2001-12-08" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/245405">20011213 WRSHDNT 2.21.00 CPU overusage</ref>
      <ref source="CONFIRM" url="http://www.denicomp.com/rshdnt.htm">http://www.denicomp.com/rshdnt.htm</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7694.php" adv="1">winsock-rshdnt-error-dos(7694)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/244580">20011208 Winsock RSHD/NT 2.20.00 CPU overusage when invalid data is send</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3659" adv="1">3659</ref>
    </refs>
    <vuln_soft>
      <prod name="winsock_rshd_nt" vendor="denicomp">
        <vers num="2.20"/>
        <vers num="2.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1185" seq="2001-1185" published="2001-12-10" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7693.php" adv="1">bsd-aio-overwrite-memory(7693)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/244583" adv="1">20011210 AIO vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3661" adv="1" patch="1">3661</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1186" seq="2001-1186" published="2001-12-11" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/244931">20011211 Microsoft IIS/5 bogus Content-length bug Memory attack</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/245100">20011212 Microsoft IIS/5.0 Content-Length DoS (proved)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7691.php" adv="1">iis-false-content-length-dos(7691)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/244892">20011211 Microsoft IIS/5 bogus Content-length bug.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3667" adv="1">3667</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1187" seq="2001-1187" published="2001-12-11" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/244908" adv="1" patch="1">20011211 CSVForm (Perl CGI) Remote Execution Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7692.php" adv="1">csvform-cgi-execute-commands(7692)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3668">3668</ref>
    </refs>
    <vuln_soft>
      <prod name="csvform" vendor="mutasem_abudahab">
        <vers num="0.1"/>
      </prod>
      <prod name="csvform_plus" vendor="mutasem_abudahab">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1188" seq="2001-1188" published="2001-12-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/244909" adv="1">20011211 SPAMMERS DELIGHT: as feeble as feeble can be</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3669" adv="1">3669</ref>
    </refs>
    <vuln_soft>
      <prod name="mailto" vendor="brian_dorricott">
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1189" seq="2001-1189" published="2001-12-13" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7698.php" adv="1">websphere-java-plaintext-passwords(7698)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245324" adv="1">20011213 IBM WebSphere on UNIX security alert !</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3682" adv="1" patch="1">3682</ref>
    </refs>
    <vuln_soft>
      <prod name="websphere_application_server" vendor="ibm">
        <vers num="3.0"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2.1"/>
        <vers num="3.0.2.2"/>
        <vers num="3.0.2.3"/>
        <vers num="3.0.2.4"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1190" seq="2001-1190" published="2001-12-12" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7706.php" adv="1" patch="1">linux-passwd-weak-encryption(7706)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-091.php3" patch="1">MDKSA-2001:091</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3683" adv="1" patch="1">3683</ref>
    </refs>
    <vuln_soft>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1191" seq="2001-1191" published="2001-12-11" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245283" adv="1">20011211 Webseal 3.8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3685" adv="1">3685</ref>
    </refs>
    <vuln_soft>
      <prod name="tivoli_secureway_policy_director" vendor="ibm">
        <vers num="3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1192" seq="2001-1192" published="2001-12-13" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a .ICA file, which is downloaded and automatically executed by the client.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245342" adv="1">20011213 Kikkert Security Advisory: Potentially serious security flaw in Citrix Client</ref>
      <ref source="BID" url="http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&amp;id=3688" adv="1" patch="1">3688</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7697">citrix-ica-gain-root(7697)</ref>
    </refs>
    <vuln_soft>
      <prod name="ica_client" vendor="citrix">
        <vers num="6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1193" seq="2001-1193" published="2001-12-13" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.eftp.org/releasehistory.html">http://www.eftp.org/releasehistory.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/413875">VU#413875</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245393" adv="1">20011213 EFTP 2.0.8.346 directory content disclosure</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3691" adv="1" patch="1">3691</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7699">eftp-dot-directory-traversal(7699)</ref>
    </refs>
    <vuln_soft>
      <prod name="eftp" vendor="khamil_landross_and_zack_jones">
        <vers num="2.0.8.346"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1194" seq="2001-1194" published="2001-12-14" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than actual packet size, or (2) fragmented packets whose size exceeds 64 kilobytes after reassembly.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0140.html">20011214 Zyxel Prestige 681 and 1600 (possibly other?) remote DoS</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0190.html">20011218 Re: Zyxel Prestige 681 and 1600 (possibly other?) remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3695" adv="1" patch="1">3695</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7704">prestige-dsl-packet-length-dos(7704)</ref>
    </refs>
    <vuln_soft>
      <prod name="prestige_1600" vendor="zyxel">
        <vers num=""/>
      </prod>
      <prod name="prestige_681" vendor="zyxel">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1195" seq="2001-1195" published="2001-12-15" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10067329.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10067329.htm</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7701.php" adv="1" patch="1">groupwise-servlet-manager-default(7701)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245871" adv="1" patch="1">20011215 Novell Groupwise servlet gateway default username and password</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3697">3697</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="5.5" edition=":enhancement_pack"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1196" seq="2001-1196" published="2001-12-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=webmin-l&amp;m=100865390306103&amp;w=2">20011218 Re: webmin 0.91 ../.. problem</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7711.php" adv="1">webmin-dot-directory-traversal(7711)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245980" adv="1">20011217 webmin 0.91 ../.. problem</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3698" adv="1" patch="1">3698</ref>
    </refs>
    <vuln_soft>
      <prod name="webmin" vendor="webmin">
        <vers num="0.91"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1197" seq="2001-1197" published="2001-12-14" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100837486611350&amp;w=2">20011214 Re: klprfax_filter symlink vulnerability</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245500" adv="1" patch="1">20011214 klprfax_filter symlink vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3694" adv="1">3694</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7700">kdeutils-klprfax-symlink(7700)</ref>
    </refs>
    <vuln_soft>
      <prod name="kdeutils" vendor="kde">
        <vers num="2.2"/>
        <vers num="2.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1198" seq="2001-1198" published="2001-12-15" modified="2017-10-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7729.php" adv="1" patch="1">hp-rlpd-create-log(7729)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/245690" adv="1" patch="1">20011215 HP-UX setuid rlpdaemon induced to make illicit file writes</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3701" adv="1" patch="1">3701</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5763">oval:org.mitre.oval:def:5763</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="11.00"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1199" seq="2001-1199" published="2001-12-17" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.agoracgi.com/security.html">http://www.agoracgi.com/security.html</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7708.php" adv="1">agora-cgi-css(7708)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246044" adv="1">20011217 Agoracgi v3.3e Cross Site Scripting Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3702" adv="1" patch="1">3702</ref>
    </refs>
    <vuln_soft>
      <prod name="agora.cgi" vendor="steve_kneizys">
        <vers num="3.2"/>
        <vers num="3.2a"/>
        <vers num="3.2b"/>
        <vers num="3.2c"/>
        <vers num="3.2d"/>
        <vers num="3.2e"/>
        <vers num="3.2f"/>
        <vers num="3.2g"/>
        <vers num="3.2h"/>
        <vers num="3.2i"/>
        <vers num="3.2j"/>
        <vers num="3.2ja"/>
        <vers num="3.2k"/>
        <vers num="3.2l"/>
        <vers num="3.2m"/>
        <vers num="3.2n"/>
        <vers num="3.2p"/>
        <vers num="3.2q"/>
        <vers num="3.2r"/>
        <vers num="3.3a"/>
        <vers num="3.3b"/>
        <vers num="3.3c"/>
        <vers num="3.3d"/>
        <vers num="3.3e"/>
        <vers num="3.3f"/>
        <vers num="3.3i"/>
        <vers num="3.3j"/>
        <vers num="4.0"/>
        <vers num="4.0a"/>
        <vers num="4.0b"/>
        <vers num="4.0c"/>
        <vers num="4.0d"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1200" seq="2001-1200" published="2001-12-17" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7713.php" adv="1">winxp-hotkey-execute-programs(7713)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246014" adv="1">20011217 Hot keys permissions bypass under XP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3703" adv="1">3703</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition="gold"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1201" seq="2001-1201" published="2001-12-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in wmcube-gdk for WMCube/GDK 0.98 allows local users to execute arbitrary code via long lines in the object description file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100863301405266&amp;w=2">20011217 New Advisory + Exploit</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/246273">20011218 wmcube-gdk is vulnerable to a local exploit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7720.php" adv="1">wmcubegdk-object-file-bo(7720)</ref>
      <ref source="CONFIRM" url="http://www.ne.jp/asahi/linux/timecop/software/wmcube-gdk-0.98p2.tar.gz">http://www.ne.jp/asahi/linux/timecop/software/wmcube-gdk-0.98p2.tar.gz</ref>
      <ref source="BID" url="http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&amp;id=3706" adv="1">3706</ref>
    </refs>
    <vuln_soft>
      <prod name="wmcube_gdk" vendor="timecop">
        <vers num="0.98"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1202" seq="2001-1202" published="2001-12-28" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100956050432351&amp;w=2">20011228 DeleGate Cross Site Scripting Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7745.php" adv="1" patch="1">delegate-proxy-css(7745)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3749">3749</ref>
    </refs>
    <vuln_soft>
      <prod name="delegate" vendor="delegate">
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="7.8.0"/>
        <vers num="7.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1203" seq="2001-1203" published="2001-12-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-095" adv="1" patch="1">DSA-095</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3750">3750</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7748">linux-gpm-format-string(7748)</ref>
    </refs>
    <vuln_soft>
      <prod name="gpm" vendor="alessandro_rubini">
        <vers num="1.17.8"/>
        <vers num="1.17.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1204" seq="2001-1204" published="2001-12-28" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247559">20011228 PHP Rocket Add-in (file transversal vulnerability)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3751" adv="1">3751</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7749">phprocket-directory-traversal(7749)</ref>
    </refs>
    <vuln_soft>
      <prod name="php_rocket_add-in" vendor="total_pc_solutions">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1205" seq="2001-1205" published="2001-12-30" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100975978324723&amp;w=2">20011230 lastlines.cgi path traversal and command execution vulns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3754" adv="1">3754</ref>
    </refs>
    <vuln_soft>
      <prod name="last_lines" vendor="matrixs_cgi_vault">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1206" seq="2001-1206" published="2001-12-30" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100975978324723&amp;w=2">20011230 lastlines.cgi path traversal and command execution vulns</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3755" adv="1">3755</ref>
    </refs>
    <vuln_soft>
      <prod name="last_lines" vendor="matrixs_cgi_vault">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1207" seq="2001-1207" published="2001-12-30" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7755.php" adv="1" patch="1">daydream-bbs-control-code-bo(7755)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3757" adv="1" patch="1">3757</ref>
    </refs>
    <vuln_soft>
      <prod name="daydream_bbs" vendor="daydream">
        <vers num="2.9"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1208" seq="2001-1208" published="2001-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100977623710528&amp;w=2">20011231 Daydream BBS Format strings issue.</ref>
    </refs>
    <vuln_soft>
      <prod name="daydream_bbs" vendor="daydream">
        <vers num="2.9"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1209" seq="2001-1209" published="2001-12-31" modified="2009-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0086.html">20011231 [VulnWatch] blackshell2: zml.cgi remote exploit</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Dec/0306.html">20011231 blackshell2: zml.cgi remote exploit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7751.php" adv="1">zml-cgi-directory-traversal(7751)</ref>
      <ref source="MISC" url="http://www.jero.cc/zml/zml.html">http://www.jero.cc/zml/zml.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3759" adv="1">3759</ref>
    </refs>
    <vuln_soft>
      <prod name="zml.cgi" vendor="abe_timmerman">
        <vers num="0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1210" seq="2001-1210" published="2001-12-30" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0297.html">20011230 Possible security problem with Cisco ubr900 series routers</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0002.html">20020103 Security Problem in Cisco ubr900 Series Routers</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7806.php" adv="1">cisco-docsis-default-strings(7806)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3758">3758</ref>
    </refs>
    <vuln_soft>
      <prod name="ubr920" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ubr924" vendor="cisco">
        <vers num=""/>
      </prod>
      <prod name="ubr925" vendor="cisco">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1211" seq="2001-1211" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://support.ipswitch.com/kb/IM-20011219-DM01.htm">http://support.ipswitch.com/kb/IM-20011219-DM01.htm</ref>
      <ref source="MISC" url="http://support.ipswitch.com/kb/IM-20020301-DM02.htm">http://support.ipswitch.com/kb/IM-20020301-DM02.htm</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7752.php" adv="1">imail-admin-domain-change(7752)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247786" adv="1">20011231 IMail Web Service User Aliases / Mailing Lists Admin Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3766" adv="1">3766</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.1"/>
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1212" seq="2001-1212" published="2001-12-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7717.php" adv="1">aktivate-shopping-css(7717)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3714">3714</ref>
    </refs>
    <vuln_soft>
      <prod name="aktivate" vendor="aktivate">
        <vers num="1.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1213" seq="2001-1213" published="2001-12-18" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7715.php" adv="1" patch="1">ftpxq-default-permissions(7715)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246285" adv="1">20011218 FTPXQ default install read/write capabilities</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3716">3716</ref>
    </refs>
    <vuln_soft>
      <prod name="ftpxq" vendor="datawizard">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1214" seq="2001-1214" published="2001-12-15" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7719.php" adv="1">unixmanual-php-command-execution(7719)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/672419">VU#672419</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247332" adv="1">20011215 *ALERT* "Unix Manual" PHP-Script allows arbitrary code execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3718">3718</ref>
    </refs>
    <vuln_soft>
      <prod name="unix_manual" vendor="marcus_s._xenakis">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1215" seq="2001-1215" published="2001-12-20" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7742.php" adv="1" patch="1">pfinger-plan-format-string(7742)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246656" adv="1">20011220 [CERT-intexxia] pfinger Format String Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3725">3725</ref>
      <ref source="CONFIRM" url="http://www.xelia.ch/unix/pfinger/ChangeLog">http://www.xelia.ch/unix/pfinger/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod name="pfinger" vendor="michael_baumer">
        <vers num="0.7.5"/>
        <vers num="0.7.6"/>
        <vers num="0.7.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1216" seq="2001-1216" published="2001-12-21" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/modplsql.pdf">http://otn.oracle.com/deploy/security/pdf/modplsql.pdf</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7727.php" adv="1" patch="1">oracle-appserver-modplsql-bo(7727)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/500203" adv="1" patch="1">VU#500203</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246663" adv="1">20011221 Buffer Overflow in Oracle 9iAS (#NISR20122001)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3726" adv="1" patch="1">3726</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1217" seq="2001-1217" published="2001-12-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/modplsql.pdf">http://otn.oracle.com/deploy/security/pdf/modplsql.pdf</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7728.php" adv="1" patch="1">oracle-appserver-modplsql-traversal(7728)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/758483" adv="1" patch="1">VU#758483</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246663" adv="1">20011221 Buffer Overflow in Oracle 9iAS (#NISR20122001)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3727" adv="1" patch="1">3727</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1218" seq="2001-1218" published="2001-12-20" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246611" adv="1">20011220 E5 (SP1) crash the X server on Solaris2.6 chinese edition</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3729">3729</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1219" seq="2001-1219" published="2001-12-20" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246649" adv="1">20011220 MSIE DoS Using javascript</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3730">3730</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1220" seq="2001-1220" published="2001-12-21" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7733.php" adv="1">dlink-ap-public-mib(7733)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246849" adv="1">20011221 D-Link DWL-1000AP can be compromised because of SNMP configuration</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3735" adv="1">3735</ref>
    </refs>
    <vuln_soft>
      <prod name="dwl-1000ap" vendor="d-link">
        <vers num="3.2.28_483"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1221" seq="2001-1221" published="2001-12-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246849" adv="1">20011221 D-Link DWL-1000AP can be compromised because of SNMP configuration</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3736" adv="1">3736</ref>
    </refs>
    <vuln_soft>
      <prod name="dwl-1000ap" vendor="d-link">
        <vers num="3.2.28_483"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1222" seq="2001-1222" published="2002-03-25" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7735.php" adv="1" patch="1">psa-php-reveal-source(7735)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246861" adv="1" patch="1">20011221 twlc advisory: plesk (psa) allows reading of .php files</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3737" adv="1" patch="1">3737</ref>
    </refs>
    <vuln_soft>
      <prod name="plesk_server_administrator" vendor="plesk">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1223" seq="2001-1223" published="2001-12-26" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7739.php" adv="1">elsa-lancom-web-administration(7739)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247274" adv="1" patch="1">20011226 Phoenix Sistemi Security Advisory: ELSA Lancom 1100 Office Security Problems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3746" adv="1">3746</ref>
    </refs>
    <vuln_soft>
      <prod name="lancom_1100_office" vendor="elsa">
        <vers num="0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1224" seq="2001-1224" published="2001-12-23" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7736.php" adv="1">adrotate-sql-execute-commands(7736)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246994" adv="1">20011223 GOBBLES CGI MARATHON #001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3739" adv="1">3739</ref>
    </refs>
    <vuln_soft>
      <prod name="adrotate_pro" vendor="les_vanbrunt">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1225" seq="2001-1225" published="2001-12-26" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7746.php" adv="1">msql-char-array-dos(7746)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247222" adv="1">20011226 msql DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3742" adv="1">3742</ref>
    </refs>
    <vuln_soft>
      <prod name="msql" vendor="hughes">
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1226" seq="2001-1226" published="2001-12-25" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7762.php" adv="1">adcycle-modify-sql-query(7762)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247126" adv="1">20011225 GOBBLES CGI MARATHON #002</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3741" adv="1">3741</ref>
    </refs>
    <vuln_soft>
      <prod name="adcycle" vendor="adcycle">
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1227" seq="2001-1227" published="2001-10-10" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-080.php3" patch="1">MDKSA-2001:080</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-072.html">RHSA-2001:072</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-115.html" patch="1">RHSA-2001:115</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3425">3425</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7271">zope-fmt-access-methods(7271)</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1228" seq="2001-1228" published="2001-11-18" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-002.txt.asc">NetBSD-SA2002-002</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/247717" adv="1" patch="1">20011230 gzip bug w/ patch..</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7882.php">gzip-long-filename-bo(7882)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3712">3712</ref>
    </refs>
    <vuln_soft>
      <prod name="gzip" vendor="gnu">
        <vers num="1.2.4"/>
        <vers num="1.2.4a"/>
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1229" seq="2001-1229" published="2001-03-12" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000387">CLA-2001:387</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98438880622976&amp;w=2">20010312 Icecast / Libshout remote vulnerabilities</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-063.html" adv="1">RHSA-2002:063</ref>
    </refs>
    <vuln_soft>
      <prod name="icecast" vendor="icecast">
        <vers num="1.3.9" prev="1"/>
      </prod>
      <prod name="libshout" vendor="libshout">
        <vers num="1.0.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1230" seq="2001-1230" published="2001-03-13" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98455723123298&amp;w=2">20010313 More Icecast remote vulnerabilities</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-089" adv="1" patch="1">DSA-089</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-063.html">RHSA-2002:063</ref>
    </refs>
    <vuln_soft>
      <prod name="icecast" vendor="icecast">
        <vers num="1.3.10" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1231" seq="2001-1231" published="2001-08-14" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://support.novell.com/padlock/details.htm" adv="1" patch="1">http://support.novell.com/padlock/details.htm</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/204672" adv="1" patch="1">20010814 Fwd: Security Alert: Groupwise - Action Required</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3189">3189</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6998">novell-groupwise-admin-privileges(6998)</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="5.5"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1232" seq="2001-1232" published="2001-08-14" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/204875" adv="1" patch="1">20010815 Groupwise Webaccess, NetWare web server, and Novell</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3188">3188</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6988">netware-get-directory-listing(6988)</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1233" seq="2001-1233" published="2001-08-14" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/204875" adv="1" patch="1">20010815 Groupwise Webaccess, NetWare web server, and Novell</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6987">netware-nds-information-leak(6987)</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise_webaccess" vendor="novell">
        <vers num="5.5"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1234" seq="2001-1234" published="2001-10-02" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="CONFIRM" url="http://prdownloads.sourceforge.net/gallery/gallery-1.2.5.tar.gz">http://prdownloads.sourceforge.net/gallery/gallery-1.2.5.tar.gz</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php" adv="1" patch="1">php-includedir-code-execution(7215)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3397" adv="1">3397</ref>
    </refs>
    <vuln_soft>
      <prod name="gallery" vendor="gallery_project">
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1235" seq="2001-1235" published="2001-10-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">pSlash PHP script 0.7 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php">php-includedir-code-execution(7215)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/847803" adv="1" patch="1">VU#847803</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3395" adv="1">3395</ref>
    </refs>
    <vuln_soft>
      <prod name="pslash" vendor="derek_leung">
        <vers num="0.70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1236" seq="2001-1236" published="2001-10-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php">php-includedir-code-execution(7215)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/847803">VU#847803</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3394" adv="1">3394</ref>
    </refs>
    <vuln_soft>
      <prod name="myphppagetool" vendor="sebastian_bunka">
        <vers num="0.4.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1237" seq="2001-1237" published="2001-10-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php">php-includedir-code-execution(7215)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/847803">VU#847803</ref>
      <ref source="CONFIRM" url="http://www.peaceworks.ca/phormation/phormation-0.9.2.tar.gz">http://www.peaceworks.ca/phormation/phormation-0.9.2.tar.gz</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3393" adv="1" patch="1">3393</ref>
    </refs>
    <vuln_soft>
      <prod name="phormation" vendor="peaceworks_computer_consulting">
        <vers num="0.9.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1238" seq="2001-1238" published="2001-07-16" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197195" adv="1">20010716 W2k: Unkillable Applications</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3033" adv="1" patch="1">3033</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6919">win2k-taskmanager-unkillable-process(6919)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_2000_terminal_services" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1239" seq="2001-1239" published="2001-06-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">PowerNet IX allows remote attackers to cause a denial of service via a port scan.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/2992">2992</ref>
    </refs>
    <vuln_soft>
      <prod name="powernet_ix" vendor="connect_inc.">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1240" seq="2001-1240" published="2001-07-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1493.html" adv="1" patch="1">ESA-20010711-02</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_linux" vendor="engardelinux">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1241" seq="2001-1241" published="2001-07-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!"  and the desired program name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0287.html">20010717 multiple vulnerabilities in un-cgi</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0349.html">20010718 Re: [Khamba Staring &lt;purrcat@edoropolis.org>] multiple</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6847.php" adv="1" patch="1">uncgi-unexecutable-cgi(6847)</ref>
      <ref source="CONFIRM" url="http://www.midwinter.com/~koreth/uncgi.html">http://www.midwinter.com/~koreth/uncgi.html</ref>
      <ref source="CONFIRM" url="http://www.midwinter.com/~koreth/uncgi-changes.html">http://www.midwinter.com/~koreth/uncgi-changes.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3057">3057</ref>
    </refs>
    <vuln_soft>
      <prod name="un-cgi" vendor="steve_grimm">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1242" seq="2001-1242" published="2001-07-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0287.html">20010717 multiple vulnerabilities in un-cgi</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0349.html">20010718 Re: [Khamba Staring &lt;purrcat@edoropolis.org>] multiple vulnerabilities in un-cgi</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6846.php" adv="1" patch="1">uncgi-dot-directory-traversal(6846)</ref>
      <ref source="CONFIRM" url="http://www.midwinter.com/~koreth/uncgi-changes.html">http://www.midwinter.com/~koreth/uncgi-changes.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3056">3056</ref>
    </refs>
    <vuln_soft>
      <prod name="un-cgi" vendor="steve_grimm">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1243" seq="2001-1243" published="2001-07-04" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6800.php" adv="1">iis-device-asp-dos(6800)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194919">20010704 NERF Advisory #4: MS IIS local and remote DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2973" adv="1" patch="1">2973</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_information_server" vendor="microsoft">
        <vers num="4.0"/>
      </prod>
      <prod name="internet_information_services" vendor="microsoft">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1244" seq="2001-1244" published="2001-07-07" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195457">20010708 Small TCP packets == very large overhead == DoS?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2997" adv="1">2997</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6824">tcp-mss-dos(6824)</ref>
    </refs>
    <vuln_soft>
      <prod name="freebsd" vendor="freebsd">
        <vers num="4.3"/>
      </prod>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.0.4"/>
        <vers num="11.11"/>
      </prod>
      <prod name="vvos" vendor="hp">
        <vers num="11.04"/>
      </prod>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
      </prod>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition=":workstation"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6a"/>
      </prod>
      <prod name="netbsd" vendor="netbsd">
        <vers num="1.5"/>
        <vers num="1.5.1"/>
      </prod>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.8"/>
        <vers num="2.9"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1245" seq="2001-1245" published="2001-07-09" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/196980">20010712 Re: Opera Browser Heap Overflow (Session Replay Attack)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6838.php" adv="1">opera-browser-header-bo(6838)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3012" adv="1">3012</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="5.0" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1246" seq="2001-1246" published="2001-06-30" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows local users and possibly remote attackers to execute arbitrary commands via shell metacharacters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/194425">20010630 php breaks safe mode</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6787.php" adv="1" patch="1">php-safemode-elevate-privileges(6787)</ref>
      <ref source="CONFIRM" url="http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz">http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-102.html">RHSA-2002:102</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-129.html">RHSA-2002:129</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-159.html">RHSA-2003:159</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2954">2954</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1247" seq="2001-1247" published="2001-12-06" modified="2012-06-25" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/194425" adv="1" patch="1">20010630 php breaks safe mode</ref>
      <ref source="CONFIRM" url="http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz">http://www.php.net/do_download.php?download_file=php-4.1.2.tar.gz</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-035.html" adv="1" patch="1">RHSA-2002:035</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.0.4pl1"/>
        <vers num="4.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1248" seq="2001-1248" published="2001-06-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/194418" adv="1">20010629 4 New vulns. vWebServer and SmallHTTP</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6769.php" adv="1">vwebserver-asp-reveal-source(6769)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2975">2975</ref>
    </refs>
    <vuln_soft>
      <prod name="vwebserver" vendor="vwebserver">
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1249" seq="2001-1249" published="2001-06-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/194418" adv="1">20010629 4 New vulns. vWebServer and SmallHTTP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2978">2978</ref>
    </refs>
    <vuln_soft>
      <prod name="vwebserver" vendor="vwebserver">
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1250" seq="2001-1250" published="2001-06-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/194418">20010629 4 New vulns. vWebServer and SmallHTTP</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6771.php" adv="1">vwebserver-long-url-dos(6771)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2979">2979</ref>
    </refs>
    <vuln_soft>
      <prod name="vwebserver" vendor="vwebserver">
        <vers num="1.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1251" seq="2001-1251" published="2001-06-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/194418">20010629 4 New vulns. vWebServer and SmallHTTP</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6771.php" adv="1">vwebserver-long-url-dos(6771)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2980">2980</ref>
    </refs>
    <vuln_soft>
      <prod name="small_http_server" vendor="max_feoktistov">
        <vers num="1.212"/>
        <vers num="2.01"/>
        <vers num="2.03"/>
        <vers num="3.0_beta"/>
      </prod>
      <prod name="vwebserver" vendor="vwebserver">
        <vers num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1252" seq="2001-1252" published="2001-09-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Network Associates PGP Keyserver 7.0 allows remote attackers to bypass authentication and access the administrative web interface via URLs that directly access cgi-bin instead of keyserver/cgi-bin for the programs (1) console, (2) cs, (3) multi_config and (4) directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0230.html">20010928 SNS-43: PGP Keyserver Permissions Misconfiguration</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7203.php" adv="1" patch="1">pgp-keyserver-http-dos(7203)</ref>
      <ref source="CONFIRM" url="http://www.pgp.com/support/product-advisories/keyserver.asp">http://www.pgp.com/support/product-advisories/keyserver.asp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3375">3375</ref>
    </refs>
    <vuln_soft>
      <prod name="keyserver" vendor="pgp">
        <vers num="7.0"/>
        <vers num="7.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1253" seq="2001-1253" published="2001-09-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Alexis 2.0 and 2.1 in COM2001 InternetPBX stores voicemail passwords in plain text in the com2001.ini file, which could allow local users to make long distance calls as other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/217200" adv="1" patch="1">20010927 Two problems with Alexis/InternetPBX from COM2001</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7205.php" adv="1" patch="1">alexis-http-plaintext-information(7205)</ref>
    </refs>
    <vuln_soft>
      <prod name="alexis_server" vendor="com2001">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1254" seq="2001-1254" published="2001-09-27" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/217200" adv="1" patch="1">20010927 Two problems with Alexis/InternetPBX from COM2001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3373">3373</ref>
    </refs>
    <vuln_soft>
      <prod name="alexis_server" vendor="com2001">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1255" seq="2001-1255" published="2001-10-02" modified="2019-10-07" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/217848" adv="1">20011002 WinMySQLadmin 1.1 Store MySQL password in clear text</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7206.php" adv="1">winmysqladmin-password-plaintext(7206)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3381">3381</ref>
    </refs>
    <vuln_soft>
      <prod name="winmysqladmin" vendor="mysql">
        <vers num="1.1"/>
      </prod>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1256" seq="2001-1256" published="2001-06-11" modified="2017-12-18" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-093.shtml" adv="1" patch="1">L-093</ref>
      <ref source="HP" url="http://online.securityfocus.com/advisories/3354" adv="1">HPSBUX0106-153</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/127435">VU#127435</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/TJSL-4Z5Q92">http://www.kb.cert.org/vuls/id/TJSL-4Z5Q92</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/188568" adv="1">20010604 yet another sym link followers</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2821">2821</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6656">hpux-kmmodreg-symlink(6656)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5628">oval:org.mitre.oval:def:5628</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1257" seq="2001-1257" published="2001-07-21" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000410">CLA-2001:410</ref>
      <ref source="CONFIRM" url="http://online.securityfocus.com/archive/1/198495">http://online.securityfocus.com/archive/1/198495</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-027.0.txt">CSSA-2001-027.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-073" adv="1" patch="1">DSA-073</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6905.php">imp-cross-site-scripting(6905)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3082">3082</ref>
    </refs>
    <vuln_soft>
      <prod name="imp" vendor="horde">
        <vers num="2.0"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1258" seq="2001-1258" published="2001-07-21" modified="2011-03-07" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000410">CLA-2001:410</ref>
      <ref source="CONFIRM" url="http://online.securityfocus.com/archive/1/198495">http://online.securityfocus.com/archive/1/198495</ref>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-027.0.txt" adv="1">CSSA-2001-027.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-073" adv="1" patch="1">DSA-073</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6906.php">imp-prefslang-gain-privileges(6906)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3083">3083</ref>
    </refs>
    <vuln_soft>
      <prod name="imp" vendor="horde">
        <vers num="2.0"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1259" seq="2001-1259" published="2001-08-07" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/202344" adv="1">20010807 Multiple vulnerabilities in Avaya Argent Office</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6953.php" adv="1">argent-office-udp-dos(6953)</ref>
    </refs>
    <vuln_soft>
      <prod name="argent_office" vendor="avaya">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1260" seq="2001-1260" published="2001-08-07" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/202344" adv="1">20010807 Multiple vulnerabilities in Avaya Argent Office</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6954.php" adv="1">argent-office-weak-encryption(6954)</ref>
    </refs>
    <vuln_soft>
      <prod name="argent_office" vendor="avaya">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1261" seq="2001-1261" published="2001-08-07" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/202344" adv="1">20010807 Multiple vulnerabilities in Avaya Argent Office</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6956.php" adv="1">argent-office-change-music(6956)</ref>
    </refs>
    <vuln_soft>
      <prod name="argent_office" vendor="avaya">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1262" seq="2001-1262" published="2001-08-07" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/202344" adv="1">20010807 Multiple vulnerabilities in Avaya Argent Office</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6955.php" adv="1">argent-office-community-string(6955)</ref>
    </refs>
    <vuln_soft>
      <prod name="argent_office" vendor="avaya">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1263" seq="2001-1263" published="2001-06-06" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/189327" adv="1">20010606 advisory for Pragma Interaccess</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2834">2834</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6658">pragma-interaccess-dos(6658)</ref>
    </refs>
    <vuln_soft>
      <prod name="interaccess" vendor="pragma_systems">
        <vers num="4.0_build_5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1264" seq="2001-1264" published="2001-07-19" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-119.shtml" adv="1" patch="1">L-119</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/420475">VU#420475</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3459" adv="1" patch="1">HPSBUX0107-161</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3072">3072</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6867">hp-virtualvault-mkacct-privilege-elevation(6867)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.04"/>
      </prod>
      <prod name="vvos" vendor="hp">
        <vers num="4.0"/>
        <vers num="4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1265" seq="2001-1265" published="2001-07-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/198297" adv="1">20010720 IBM TFTP Server for Java vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3076" adv="1">3076</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6864">ibm-tftp-directory-traversal(6864)</ref>
    </refs>
    <vuln_soft>
      <prod name="alphaworks_tftp_server" vendor="ibm">
        <vers num="1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1266" seq="2001-1266" published="2001-07-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0002.html" adv="1">http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0002.html</ref>
      <ref source="CONFIRM" url="http://dnhttpd.sourceforge.net/changelog.html">http://dnhttpd.sourceforge.net/changelog.html</ref>
    </refs>
    <vuln_soft>
      <prod name="dnhttpd" vendor="doug_neal">
        <vers num="0.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1267" seq="2001-1267" published="2001-07-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://alpha.gnu.org/gnu/tar/tar-1.13.25.tar.gz">ftp://alpha.gnu.org/gnu/tar/tar-1.13.25.tar.gz</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000538">CLA-2002:538</ref>
      <ref source="HP" url="http://online.securityfocus.com/advisories/4514">HPSBTL0209-068</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/196445" adv="1" patch="1">20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-47800-1">47800</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10224.php" adv="1">archive-extraction-directory-traversal(10224)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:066">MDKSA-2002:066</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-096.html" adv="1" patch="1">RHSA-2002:096</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-138.html">RHSA-2002:138</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-218.html">RHSA-2003:218</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3024">3024</ref>
    </refs>
    <vuln_soft>
      <prod name="tar" vendor="gnu">
        <vers num="1.13.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1268" seq="2001-1268" published="2001-07-12" modified="2010-05-25" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/196445" adv="1" patch="1">20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-47800-1">47800</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000928.1-1">1000928</ref>
      <ref source="CONFIRM" url="http://www.info-zip.org/pub/infozip/UnZip.html">http://www.info-zip.org/pub/infozip/UnZip.html</ref>
    </refs>
    <vuln_soft>
      <prod name="unzip" vendor="info-zip">
        <vers num="5.42" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1269" seq="2001-1269" published="2001-07-12" modified="2010-05-25" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/196445" adv="1" patch="1">20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-47800-1">47800</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1000928.1-1">1000928</ref>
      <ref source="CONFIRM" url="http://www.info-zip.org/pub/infozip/UnZip.html">http://www.info-zip.org/pub/infozip/UnZip.html</ref>
    </refs>
    <vuln_soft>
      <prod name="unzip" vendor="info-zip">
        <vers num="5.42" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1270" seq="2001-1270" published="2001-07-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/196445" adv="1" patch="1">20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers</ref>
      <ref source="MISC" url="http://www.security.nnov.ru/advisories/archdt.asp" adv="1">http://www.security.nnov.ru/advisories/archdt.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="pkzip" vendor="pkware">
        <vers num="4.00" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1271" seq="2001-1271" published="2001-07-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a ..  (dot dot) attack on archived filenames.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/196445" adv="1" patch="1">20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers</ref>
      <ref source="MISC" url="http://www.security.nnov.ru/advisories/archdt.asp" adv="1">http://www.security.nnov.ru/advisories/archdt.asp</ref>
    </refs>
    <vuln_soft>
      <prod name="rar" vendor="rarsoft">
        <vers num="2.02" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1272" seq="2001-1272" published="2001-12-06" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-092" adv="1">DSA-092</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7669.php" adv="1" patch="1">wmtv-execute-commands(7669)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3658" adv="1">3658</ref>
    </refs>
    <vuln_soft>
      <prod name="wmtv" vendor="wliang">
        <vers num="0.6.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1273" seq="2001-1273" published="2001-02-12" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-045.shtml" adv="1" patch="1">L-045</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-013.html" adv="1" patch="1">RHSA-2001:013</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.17" prev="1" edition="pre14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1274" seq="2001-1274" published="2001-01-23" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000375">CLA-2001:375</ref>
      <ref source="FREEBSD" url="http://marc.info/?l=bugtraq&amp;m=98089552030459&amp;w=2">FreeBSD-SA-01:16</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txt" adv="1">CSSA-2001-006.0</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-013" adv="1" patch="1">DSA-013</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3">MDKSA-2001:014</ref>
      <ref source="CONFIRM" url="http://www.mysql.com/documentation/mysql/bychapter/manual_News.html#News-3.23.3">http://www.mysql.com/documentation/mysql/bychapter/manual_News.html#News-3.23.3</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-003.html">RHSA-2001:003</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23.31" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1275" seq="2001-1275" published="2001-01-19" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="FREEBSD" url="http://marc.info/?l=bugtraq&amp;m=98089552030459&amp;w=2">FreeBSD-SA-01:16</ref>
      <ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txt">CSSA-2001-006.0</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3">MDKSA-2001:014</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-003.html" adv="1" patch="1">RHSA-2001:003</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23.31" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1276" seq="2001-1276" published="2001-06-21" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/6.2/updates/IMNX-2001-62-004-01">IMNX-2001-62-004-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99317439131174&amp;w=2">20010621 ispell update -- Immunix OS 6.2</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-058.php3">MDKSA-2001:058</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-074.html" adv="1" patch="1">RHSA-2001:074</ref>
    </refs>
    <vuln_soft>
      <prod name="ispell" vendor="itcorp">
        <vers num="3.1.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1277" seq="2001-1277" published="2001-06-11" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page whose name contains shell metacharacters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99227597227747&amp;w=2">20010611 man 1.5h10 + man 1.5i-4 exploits</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-072.html" adv="1" patch="1">RHSA-2001:072</ref>
      <ref source="MISC" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=41805">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=41805</ref>
    </refs>
    <vuln_soft>
      <prod name="makewhatis" vendor="wolfram_schneider">
        <vers num="1.5i2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1278" seq="2001-1278" published="2001-10-10" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-080.php3">MDKSA-2001:080</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-115.html" adv="1" patch="1">RHSA-2001:115</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3425">3425</ref>
    </refs>
    <vuln_soft>
      <prod name="zope" vendor="zope">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1279" seq="2001-1279" published="2001-07-17" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-025.0.txt">CSSA-2002-025.0</ref>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:48.tcpdump.asc">FreeBSD-SA-01:48</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000480">CLA-2002:480</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7006.php">tcpdump-afs-rpc-bo(7006)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/797201" adv="1">VU#797201</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-032.php">MDKSA-2002:032</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-089.html" adv="1" patch="1">RHSA-2001:089</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3065">3065</ref>
    </refs>
    <vuln_soft>
      <prod name="tcpdump" vendor="lbl">
        <vers num="3.6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1280" seq="2001-1280" published="2001-10-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html">20011011 Vulnerabilities in Ipswitch IMail Server 7.04</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3424">3424</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1281" seq="2001-1281" published="2001-10-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html" adv="1">20011011 Vulnerabilities in Ipswitch IMail Server 7.04</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3429">3429</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1282" seq="2001-1282" published="2001-10-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html">20011011 Ipswitch Imail 7.04 vulnerabilities</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3426">3426</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1283" seq="2001-1283" published="2001-10-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html">20011011 Ipswitch Imail 7.04 vulnerabilities</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3427">3427</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1284" seq="2001-1284" published="2001-10-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html">20011011 Ipswitch Imail 7.04 vulnerabilities</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3428">3428</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1285" seq="2001-1285" published="2001-10-12" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html">20011011 Ipswitch Imail 7.04 vulnerabilities</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3432">3432</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1286" seq="2001-1286" published="2001-10-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html">20011011 Ipswitch Imail 7.04 vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/261096" adv="1" patch="1">20020310 IMail Account hijack through the Web Interface</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3432">3432</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1287" seq="2001-1287" published="2001-10-12" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0083.html">20011012 def-2001-29</ref>
      <ref source="MISC" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3431">3431</ref>
    </refs>
    <vuln_soft>
      <prod name="imail" vendor="ipswitch">
        <vers num="6.0.2"/>
        <vers num="6.0.6"/>
        <vers num="7.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1288" seq="2001-1288" published="2001-07-27" modified="2019-04-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99640583014377&amp;w=2">20010729 Re: w2k dos</ref>
      <ref source="VULN-DEV" url="http://marc.info/?l=vuln-dev&amp;m=99651044701417&amp;w=2">20010730 RE: bug w2k</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/200118" adv="1">20010727 bug w2k</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/200985">20010731 NT TS / Win 2K and F7 - Enter bug</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/201151">20010801 F7-Enter bug details &amp; workaround</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3115">3115</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1289" seq="2001-1289" published="2001-07-29" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0748.html" adv="1">20010730 ADV: Quake 3 Arena 1.29f/g Vulnerability</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3123">3123</ref>
    </refs>
    <vuln_soft>
      <prod name="quake_3_arena" vendor="id_software">
        <vers num="1.29f"/>
        <vers num="1.29g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1290" seq="2001-1290" published="2001-06-28" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0386.html">20010627 Active Web Classifieds failure to authenticate leads to arbitrary code execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2942">2942</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6754">active-classifieds-admin-access(6754)</ref>
    </refs>
    <vuln_soft>
      <prod name="active_classifieds" vendor="active_web_suite_technologies">
        <vers num="1.0" edition=":free"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1291" seq="2001-1291" published="2001-07-12" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the server via brute force password guessing.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/196957" adv="1">20010712 3Com TelnetD</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3034" adv="1">3034</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6855">3com-telnetd-brute-force(6855)</ref>
    </refs>
    <vuln_soft>
      <prod name="superstack_ii_ps_hub" vendor="3com">
        <vers num="40"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1292" seq="2001-1292" published="2001-08-13" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0160.html">20010813 Sambar Telnet Proxy/Server multiple vulnerablietis</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6973.php" adv="1">sambar-telnet-bo(6973)</ref>
    </refs>
    <vuln_soft>
      <prod name="sambar_server" vendor="sambar">
        <vers num="5.0"/>
        <vers num="5.1" edition="site2"/>
        <vers num="5.1" edition="site3"/>
        <vers num="5.2" edition="beta2"/>
        <vers num="5.2" edition="beta3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1293" seq="2001-1293" published="2001-09-26" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in web server of 3com HomeConnect Cable Modem External with USB (#3CR29223) allows remote attackers to cause a denial of service (crash) via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0217.html">20010926 3Com(r) HomeConnect(r) Cable Modem    Denial of Service</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/500027" adv="1">VU#500027</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3366">3366</ref>
    </refs>
    <vuln_soft>
      <prod name="3cr29223" vendor="3com">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1294" seq="2001-1294" published="2001-08-22" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7022.php" adv="1">inetserv-webmail-bo(7022)</ref>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0001&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=4592">20000117 Remote Buffer Exploit - InetServ 3.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3224">3224</ref>
    </refs>
    <vuln_soft>
      <prod name="inetserv" vendor="avtronics">
        <vers num="3.0"/>
        <vers num="3.1.1"/>
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1295" seq="2001-1295" published="2001-08-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cerberus FTP Server 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the CD command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.greenepa.net/~averett/cerberus-releasenotes.htm#ReleaseNotes">http://www.greenepa.net/~averett/cerberus-releasenotes.htm#ReleaseNotes</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7004.php" adv="1">cerberus-ftp-directory-traversal(7004)</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5SP0M0055W.html">http://www.securiteam.com/windowsntfocus/5SP0M0055W.html</ref>
    </refs>
    <vuln_soft>
      <prod name="cerberus_ftp_server" vendor="grant_averett">
        <vers num="1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1296" seq="2001-1296" published="2001-10-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">More.groupware PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php" adv="1" patch="1">php-includedir-code-execution(7215)</ref>
      <ref source="MISC" url="http://www.moregroupware.org/index.php?action=detail&amp;news_id=24">http://www.moregroupware.org/index.php?action=detail&amp;news_id=24</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3383" adv="1">3383</ref>
    </refs>
    <vuln_soft>
      <prod name="more.groupware" vendor="marc_logemann">
        <vers num="0.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1297" seq="2001-1297" published="2001-10-02" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in Actionpoll PHP script before 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="CONFIRM" url="http://sourceforge.net/project/shownotes.php?release_id=58331">http://sourceforge.net/project/shownotes.php?release_id=58331</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php" adv="1" patch="1">php-includedir-code-execution(7215)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3384" adv="1">3384</ref>
    </refs>
    <vuln_soft>
      <prod name="actionpoll" vendor="actionpoll">
        <vers num="1.1.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1298" seq="2001-1298" published="2001-10-02" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php" adv="1" patch="1">php-includedir-code-execution(7215)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3385" adv="1">3385</ref>
    </refs>
    <vuln_soft>
      <prod name="webodex" vendor="grant_horwood">
        <vers num="1.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1299" seq="2001-1299" published="2001-10-02" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Zorbat Zorbstats PHP script before 0.9 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html">20011002 results of semi-automatic source code audit</ref>
      <ref source="CONFIRM" url="http://www.come.to/zorbat/">http://www.come.to/zorbat/</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7215.php" adv="1" patch="1">php-includedir-code-execution(7215)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/847803">VU#847803</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-53RJKV">http://www.kb.cert.org/vuls/id/JARL-53RJKV</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3386" adv="1">3386</ref>
    </refs>
    <vuln_soft>
      <prod name="zorbstats" vendor="zorbat">
        <vers num="0.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1300" seq="2001-1300" published="2002-06-25" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7045.php" adv="1" patch="1">dynuftp-dot-directory-traversal(7045)</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5KP0N0A55M.html" adv="1" patch="1">http://www.securiteam.com/windowsntfocus/5KP0N0A55M.html</ref>
    </refs>
    <vuln_soft>
      <prod name="dynu_ftp_server" vendor="dynu_systems_inc.">
        <vers num="1.04"/>
        <vers num="1.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1301" seq="2001-1301" published="2001-08-07" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0093.html" adv="1">20010807 rcs2log</ref>
      <ref source="CONFIRM" url="http://savannah.gnu.org/cgi-bin/viewcvs/emacs/emacs/lib-src/rcs2log?only_with_tag=EMACS_PRETEST_21_0_95">http://savannah.gnu.org/cgi-bin/viewcvs/emacs/emacs/lib-src/rcs2log?only_with_tag=EMACS_PRETEST_21_0_95</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/11210.php">rcs2log-tmp-symlink(11210)</ref>
    </refs>
    <vuln_soft>
      <prod name="emacs" vendor="gnu">
        <vers num="20.4"/>
      </prod>
      <prod name="xemacs" vendor="xemacs">
        <vers num="21.1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1302" seq="2001-1302" published="2001-07-18" modified="2019-04-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0107&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=1911">20010718 Changing NT/2000 accounts password from the command line</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3063" adv="1">3063</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6876">win2k-change-network-passwords(6876)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1303" seq="2001-1303" published="2001-07-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197566">20010718 Firewall-1 Information leak</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3058">3058</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6857">fw1-securemote-gain-information(6857)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.0"/>
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1304" seq="2001-1304" published="2001-08-03" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0048.html" adv="1">20010803 Denial of Service in SHOUTcast Server 1.8.2 Linux/w32/?</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6938.php" adv="1">shoutcast-http-field-bo(6938)</ref>
    </refs>
    <vuln_soft>
      <prod name="shoutcast_server" vendor="nullsoft">
        <vers num="1.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1305" seq="2001-1305" published="2001-08-17" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is processed by Internet Explorer.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99851887024728&amp;w=2">20010822 Hexyn / Securax Advisory #22 - ICQ Forced Auto-Add Users</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7028.php" adv="1" patch="1">icq-auto-add-user(7028)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3226">3226</ref>
    </refs>
    <vuln_soft>
      <prod name="icq" vendor="mirabilis">
        <vers num="2000.0a"/>
        <vers num="2000.0b_build3278"/>
        <vers num="2001a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1306" seq="2001-1306" published="2001-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011102-01-I" adv="1">20011102-01-I</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1" patch="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/276944" adv="1">VU#276944</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/JPLA-4WESMM">http://www.kb.cert.org/vuls/id/JPLA-4WESMM</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_directory_server" vendor="sun">
        <vers num="4.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1307" seq="2001-1307" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011102-01-I" adv="1">20011102-01-I</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1" patch="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/276944">VU#276944</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/JPLA-4WESMM">http://www.kb.cert.org/vuls/id/JPLA-4WESMM</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3038" adv="1">3038</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6893">iplanet-ldap-protos-bo(6893)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_directory_server" vendor="sun">
        <vers num="4.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1308" seq="2001-1308" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011102-01-I" adv="1" patch="1">20011102-01-I</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/276944">VU#276944</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/JPLA-4WESMM">http://www.kb.cert.org/vuls/id/JPLA-4WESMM</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3039" adv="1">3039</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6898">iplanet-ldap-protos-format-string(6898)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_directory_server" vendor="sun">
        <vers num="4.1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1309" seq="2001-1309" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/505564">VU#505564</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y">http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3040" adv="1">3040</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6894">secureway-ldap-protos-dos(6894)</ref>
    </refs>
    <vuln_soft>
      <prod name="secureway_directory" vendor="ibm">
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1310" seq="2001-1310" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/505564">VU#505564</ref>
      <ref source="MISC" url="http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y">http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3040">3040</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6894">secureway-ldap-protos-dos(6894)</ref>
    </refs>
    <vuln_soft>
      <prod name="secureway_directory" vendor="ibm">
        <vers num="3.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1311" seq="2001-1311" published="2001-07-16" modified="2018-10-19" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/583184">VU#583184</ref>
      <ref source="CONFIRM" url="http://www.notes.net/r5fixlist.nsf/Search!SearchView&amp;Query=DWUU4W6NC8">http://www.notes.net/r5fixlist.nsf/Search!SearchView&amp;Query=DWUU4W6NC8</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/314909/30/25520/threaded">20030313 R7-0012: Lotus Notes/Domino R6-beta PROTOS LDAP Denial of Service Regression</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3041">3041</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6895">domino-ldap-protos-bo(6895)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_r5" vendor="ibm">
        <vers num="5.0.7a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1312" seq="2001-1312" published="2001-07-16" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/583184">VU#583184</ref>
      <ref source="CONFIRM" url="http://www.notes.net/r5fixlist.nsf/Search!SearchView&amp;Query=DWUU4W6NC8">http://www.notes.net/r5fixlist.nsf/Search!SearchView&amp;Query=DWUU4W6NC8</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3042">3042</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6896">domino-ldap-protos-format-string(6896)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_r5" vendor="ibm">
        <vers num="5.0.7a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1313" seq="2001-1313" published="2001-07-16" modified="2018-08-13" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/583184">VU#583184</ref>
      <ref source="CONFIRM" url="http://www.notes.net/r5fixlist.nsf/Search!SearchView&amp;Query=DWUU4W6NC8">http://www.notes.net/r5fixlist.nsf/Search!SearchView&amp;Query=DWUU4W6NC8</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino_r5" vendor="ibm">
        <vers num="5.0.7a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1314" seq="2001-1314" published="2001-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0770.html">20010731 RE: CERT Advisory CA-2001-18, Critical Path directory products ar e vulnerable</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/657547">VU#657547</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM">http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3124" adv="1">3124</ref>
    </refs>
    <vuln_soft>
      <prod name="injoin_directory_server" vendor="critical_path">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="4.0"/>
      </prod>
      <prod name="livecontent_directory" vendor="critical_path">
        <vers num="8a3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1315" seq="2001-1315" published="2001-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0770.html">20010731 RE: CERT Advisory CA-2001-18, Critical Path directory products ar e vulnerable</ref>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/657547">VU#657547</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM">http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM</ref>
    </refs>
    <vuln_soft>
      <prod name="injoin_directory_server" vendor="critical_path">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="4.0"/>
      </prod>
      <prod name="livecontent_directory" vendor="critical_path">
        <vers num="8a3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1316" seq="2001-1316" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/688960">VU#688960</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JPLA-4WESNA">http://www.kb.cert.org/vuls/id/JPLA-4WESNA</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3044" adv="1">3044</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6897">teamware-ldap-protos-bo(6897)</ref>
    </refs>
    <vuln_soft>
      <prod name="teamware_office" vendor="teamware">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1317" seq="2001-1317" published="2001-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for certain BER object types, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/688960">VU#688960</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JPLA-4WESNA">http://www.kb.cert.org/vuls/id/JPLA-4WESNA</ref>
    </refs>
    <vuln_soft>
      <prod name="teamware_office" vendor="teamware">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1318" seq="2001-1318" published="2001-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerabilities in Qualcomm Eudora WorldMail Server may allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/717380">VU#717380</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JPLA-4WESNA">http://www.kb.cert.org/vuls/id/JPLA-4WESNA</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3043" adv="1">3043</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora_worldmail_server" vendor="qualcomm">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1319" seq="2001-1319" published="2001-07-16" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/763400">VU#763400</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/CFCN-4YAQC7">http://www.kb.cert.org/vuls/id/CFCN-4YAQC7</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3045">3045</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6899">exchange-ldap-protos-dos(6899)</ref>
    </refs>
    <vuln_soft>
      <prod name="exchange_server" vendor="microsoft">
        <vers num="5.5"/>
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1320" seq="2001-1320" published="2001-07-16" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/765256">VU#765256</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JPLA-4WESNK">http://www.kb.cert.org/vuls/id/JPLA-4WESNK</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3046" adv="1">3046</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6900">pgp-keyserver-ldap-bo(6900)</ref>
    </refs>
    <vuln_soft>
      <prod name="keyserver" vendor="pgp">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1321" seq="2001-1321" published="2001-07-16" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-116.shtml" adv="1" patch="1">L-116</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-18.html" adv="1">CA-2001-18</ref>
      <ref source="MISC" url="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/">http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/869184">VU#869184</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JPLA-4WESNV">http://www.kb.cert.org/vuls/id/JPLA-4WESNV</ref>
    </refs>
    <vuln_soft>
      <prod name="internet_directory" vendor="oracle">
        <vers num="2.1.1"/>
        <vers num="3.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1322" seq="2001-1322" published="2001-07-10" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000404">CLA-2001:404</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-024-01">IMNX-2001-70-024-01</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-063">DSA-063</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6657.php" adv="1">xinetd-insecure-permissions(6657)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-055.php3">MDKSA-2001:055</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1469.html" adv="1">ESA-20010621-01</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-075.html">RHSA-2001:075</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2826">2826</ref>
    </refs>
    <vuln_soft>
      <prod name="xinetd" vendor="xinetd">
        <vers num="2.1.8.8"/>
        <vers num="2.1.8.8_pre3"/>
        <vers num="2.1.8.9_pre1"/>
        <vers num="2.1.8.9_pre2"/>
        <vers num="2.1.8.9_pre3"/>
        <vers num="2.1.8.9_pre4"/>
        <vers num="2.1.8.9_pre5"/>
        <vers num="2.1.8.9_pre7"/>
        <vers num="2.1.8.9_pre8"/>
        <vers num="2.1.8.9_pre9"/>
        <vers num="2.1.8.9_pre10"/>
        <vers num="2.1.8.9_pre11"/>
        <vers num="2.1.8.9_pre12"/>
        <vers num="2.1.8.9_pre13"/>
        <vers num="2.1.8.9_pre14"/>
        <vers num="2.1.8.9_pre15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1323" seq="2001-1323" published="2001-05-16" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-022-01">IMNX-2001-70-022-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98826223517788&amp;w=2">20010426 Security advisory: krb5 ftpd buffer overflows</ref>
      <ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/ftpbuf.txt">http://web.mit.edu/kerberos/www/advisories/ftpbuf.txt</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-060.html" adv="1" patch="1">RHSA-2001:060</ref>
    </refs>
    <vuln_soft>
      <prod name="kerberos" vendor="mit">
        <vers num="5-1.2.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1324" seq="2001-1324" published="2001-06-26" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://multivac.cwru.edu/idtools/admin_idtools.tar.bz2">http://multivac.cwru.edu/idtools/admin_idtools.tar.bz2</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1001839">1001839</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2934" adv="1" patch="1">2934</ref>
    </refs>
    <vuln_soft>
      <prod name="idtools" vendor="paul_jarc">
        <vers num="2001-05-31"/>
        <vers num="2001-06-08"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1325" seq="2001-1325" published="2001-04-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/3AE02004.57FDF958@guninski.com">20010420 XML scripting in IE, Outlook Express</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2633" adv="1" patch="1">2633</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6448">ie-xml-stylesheets-scripting(6448)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.5"/>
      </prod>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1326" seq="2001-1326" published="2001-05-29" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/187128" adv="1">20010528 feeble.hey!dora.exploit part.II</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2796" adv="1" patch="1">2796</ref>
    </refs>
    <vuln_soft>
      <prod name="eudora" vendor="qualcomm">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1327" seq="2001-1327" published="2001-05-24" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">pmake before 2.1.35 in Turbolinux 6.05 and earlier is installed with setuid root privileges, which could allow local users to gain privileges by exploiting vulnerabilities in pmake or programs that are used by pmake.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/9988.php">pmake-binary-gain-privileges(9988)</ref>
      <ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2001-May/000313.html" adv="1" patch="1">TLSA2001024</ref>
    </refs>
    <vuln_soft>
      <prod name="pmake" vendor="berkeley_softworks">
        <vers num="2.1.35" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1328" seq="2001-1328" published="2001-06-22" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2001.03" adv="1" patch="1">AA-2001.03</ref>
      <ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/203">00203</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-103.shtml">L-103</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6828">solaris-ypbind-bo(6828)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1844">oval:org.mitre.oval:def:1844</ref>
    </refs>
    <vuln_soft>
      <prod name="sunos" vendor="sun">
        <vers num="5.4" edition=":x86"/>
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
        <vers num="5.6" edition=":x86"/>
        <vers num="5.7" edition=":x86"/>
        <vers num="5.8" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1329" seq="2001-1329" published="2001-06-11" modified="2017-04-28" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0133.html" adv="1">20010611 rsh bufferoverflow on AIX 4.2</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1330" seq="2001-1330" published="2001-06-11" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0133.html" adv="1">20010611 rsh bufferoverflow on AIX 4.2</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1331" seq="2001-1331" published="2001-05-03" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://online.securityfocus.com/advisories/3307">http://online.securityfocus.com/advisories/3307</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-056" adv="1" patch="1">DSA-056</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2720">2720</ref>
    </refs>
    <vuln_soft>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
      <prod name="debian" vendor="progeny">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1332" seq="2001-1332" published="2001-05-10" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000384">CLA-2001:384</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000386">CLA-2001:386</ref>
      <ref source="SUSE" url="http://lists2.suse.com/archive/suse-security-announce/2001-Mar/0000.html" adv="1" patch="1">SuSE-SA:2002:005</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-048.php3" adv="1" patch="1">MDKSA-2001:048</ref>
    </refs>
    <vuln_soft>
      <prod name="cups" vendor="easy_software_products">
        <vers num="1.1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1333" seq="2001-1333" published="2001-05-10" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000384">CLA-2001:384</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000386">CLA-2001:386</ref>
      <ref source="SUSE" url="http://lists2.suse.com/archive/suse-security-announce/2001-Mar/0000.html" adv="1" patch="1">SuSE-SA:2002:005</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-048.php3" adv="1" patch="1">MDKSA-2001:048</ref>
    </refs>
    <vuln_soft>
      <prod name="cups" vendor="easy_software_products">
        <vers num="1.1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1334" seq="2001-1334" published="2002-05-19" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0126.html">20010515 PHPSlash : potential vulnerability in URL blocks</ref>
      <ref source="CONFIRM" url="http://marc.info/?l=phpslash&amp;m=99029398904419&amp;w=2">http://marc.info/?l=phpslash&amp;m=99029398904419&amp;w=2</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/9990.php">phpslash-block-read-files(9990)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2724">2724</ref>
    </refs>
    <vuln_soft>
      <prod name="phpslash" vendor="phpslash">
        <vers num="0.5.3.2"/>
        <vers num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1335" seq="2001-1335" published="2001-05-27" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0252.html">20010527 CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6606.php" adv="1">cesarftp-directory-traversal(6606)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2786">2786</ref>
    </refs>
    <vuln_soft>
      <prod name="cesarftp" vendor="aclogic">
        <vers num="0.98b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1336" seq="2001-1336" published="2001-05-28" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0252.html">20010527 CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6608.php" adv="1">cesarftp-settings-plaintext-password(6608)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2785">2785</ref>
    </refs>
    <vuln_soft>
      <prod name="cesarftp" vendor="aclogic">
        <vers num="0.98b" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1337" seq="2001-1337" published="2001-05-21" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6594.php" adv="1">ipcchip-http-dos(6594)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186418">20010524 IPC@Chip Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2774" adv="1">2774</ref>
    </refs>
    <vuln_soft>
      <prod name="ipc_at_chip_embedded-webserver" vendor="beck_ipc_gmbh">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1338" seq="2001-1338" published="2001-05-24" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html">20010602 IPC@Chip - Fixes</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6595.php" adv="1">ipcchip-telnet-verify-account(6595)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/198979">VU#198979</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186418" adv="1" patch="1">20010524 IPC@Chip Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2773">2773</ref>
    </refs>
    <vuln_soft>
      <prod name="ipc_at_chip_telnetd_server" vendor="beck_ipc_gmbh">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1339" seq="2001-1339" published="2001-05-24" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html">20010602 IPC@Chip - Fixes</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6605.php" adv="1">ipcchip-telnet-bruteforce-passwords(6605)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/198979">VU#198979</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186418">20010524 IPC@Chip Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2771" adv="1" patch="1">2771</ref>
    </refs>
    <vuln_soft>
      <prod name="ipc_at_chip_embedded-webserver" vendor="beck_ipc_gmbh">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1340" seq="2001-1340" published="2002-05-21" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html">20010602 IPC@Chip - Fixes</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6596.php" adv="1">ipcchip-telnet-admin-lockout(6596)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/756019">VU#756019</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186418">20010524 IPC@Chip Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2772" adv="1" patch="1">2772</ref>
    </refs>
    <vuln_soft>
      <prod name="ipc_at_chip_telnetd_server" vendor="beck_ipc_gmbh">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1341" seq="2001-1341" published="2001-05-24" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html">20010602 IPC@Chip - Fixes</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6600.php" adv="1">ipcchip-chipcfg-gain-information(6600)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/574739">VU#574739</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186418">20010524 IPC@Chip Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2767" adv="1" patch="1">2767</ref>
    </refs>
    <vuln_soft>
      <prod name="ipc_at_chip_embedded-webserver" vendor="beck_ipc_gmbh">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1342" seq="2001-1342" published="2001-05-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugs.apache.org/index.cgi/full/7522">http://bugs.apache.org/index.cgi/full/7522</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99054258728748&amp;w=2">20010522 [Announce] Apache 1.3.20 Released</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/176144">20010412 Apache Win32 8192 chars string bug</ref>
      <ref source="CONFIRM" url="http://www.apacheweek.com/issues/01-05-25">http://www.apacheweek.com/issues/01-05-25</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6527.php" adv="1" patch="1">apache-server-dos(6527)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2740">2740</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.12" edition=":win32"/>
        <vers num="1.3.14" edition=":win32"/>
        <vers num="1.3.15" edition=":win32"/>
        <vers num="1.3.16" edition=":win32"/>
        <vers num="1.3.17" edition=":win32"/>
        <vers num="1.3.18" edition=":win32"/>
        <vers num="1.3.19" edition=":win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1343" seq="2001-1343" published="2001-06-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0142.html">20010612 bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2861" adv="1" patch="1">2861</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6685">webstore-cgi-command-execution(6685)</ref>
    </refs>
    <vuln_soft>
      <prod name="webstore_400" vendor="cgicentral">
        <vers num="4.14"/>
      </prod>
      <prod name="webstore_400cs" vendor="cgicentral">
        <vers num="4.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1344" seq="2001-1344" published="2001-06-12" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0142.html">20010612 bug</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2860" adv="1">2860</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6685">webstore-cgi-command-execution(6685)</ref>
    </refs>
    <vuln_soft>
      <prod name="webstore_400" vendor="cgicentral">
        <vers num="4.14"/>
      </prod>
      <prod name="webstore_400cs" vendor="cgicentral">
        <vers num="4.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1345" seq="2001-1345" published="2001-06-05" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, which allows local users to gain privileges by modifying the PATH to point to a Trojan horse program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-06/0005.html">20010604 Fatal flaw in BestCrypt &lt;= v0.7 (Linux)</ref>
      <ref source="CONFIRM" url="http://www.jetico.com/index.htm#/linux.htm">http://www.jetico.com/index.htm#/linux.htm</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2820" adv="1" patch="1">2820</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6648">bestcrypt-bctool-gain-privileges(6648)</ref>
    </refs>
    <vuln_soft>
      <prod name="bestcrypt" vendor="jetico">
        <vers num="0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1346" seq="2001-1346" published="2001-05-18" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="1.2" CVSS_base_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0184.html">20010518 tmp-races in ARCservIT Unix Client</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2741">2741</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2748">2748</ref>
    </refs>
    <vuln_soft>
      <prod name="arcserve_backup" vendor="ca">
        <vers num="6.61"/>
        <vers num="6.63"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1347" seq="2001-1347" published="2001-05-24" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0232.html">20010524 Elevation of privileges with debug registers on Win2K</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6590.php" adv="1" patch="1">win2k-debug-elevate-privileges(6590)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2764" adv="1" patch="1">2764</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1348" seq="2001-1348" published="2001-05-28" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0260.html">20010528 TWIG SQL query bugs</ref>
      <ref source="MISC" url="http://twig.screwdriver.net/index.php3">http://twig.screwdriver.net/index.php3</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6619.php" adv="1" patch="1">twig-webmail-query-modification(6619)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2791" adv="1" patch="1">2791</ref>
    </refs>
    <vuln_soft>
      <prod name="twig" vendor="twig_development_team">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0_beta1"/>
        <vers num="2.0_beta2"/>
        <vers num="2.0_beta3"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.3"/>
        <vers num="2.3.1"/>
        <vers num="2.3.2"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="2.6"/>
        <vers num="2.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1349" seq="2001-1349" published="2001-05-28" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.7" CVSS_base_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://archives.neohapsis.com/archives/sendmail/2001-q2/0001.html">http://archives.neohapsis.com/archives/sendmail/2001-q2/0001.html</ref>
      <ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_sm8120.html" adv="1" patch="1">20010528 Unsafe Signal Handling in Sendmail</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-106.html">RHSA-2001:106</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6633.php">sendmail-signal-handling(6633)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/187127" adv="1">20010529 sendmail 8.11.4 and 8.12.0.Beta10 available (fwd)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2794" adv="1" patch="1">2794</ref>
    </refs>
    <vuln_soft>
      <prod name="sendmail" vendor="sendmail">
        <vers num="8.10"/>
        <vers num="8.10.1"/>
        <vers num="8.10.2"/>
        <vers num="8.11.0"/>
        <vers num="8.11.1"/>
        <vers num="8.11.2"/>
        <vers num="8.11.3"/>
        <vers num="8.12" edition="beta7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1350" seq="2001-1350" published="2001-11-25" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://marc.info/?l=bugtraq&amp;w=2&amp;r=1&amp;s=namazu&amp;q=b">RHSA-2001:162</ref>
      <ref source="MISC" url="http://search.namazu.org/ml/namazu-devel-ja/msg02114.html">http://search.namazu.org/ml/namazu-devel-ja/msg02114.html</ref>
    </refs>
    <vuln_soft>
      <prod name="namazu" vendor="namazu">
        <vers num="2.0.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1351" seq="2001-1351" published="2001-12-25" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://marc.info/?l=bugtraq&amp;w=2&amp;r=1&amp;s=namazu&amp;q=b">RHSA-2001:162</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7875">linux-namazu-css(7875)</ref>
    </refs>
    <vuln_soft>
      <prod name="namazu" vendor="namazu">
        <vers num="2.0.8" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1352" seq="2001-1352" published="2001-12-27" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100947261916155&amp;w=2">20011227 Re: [RHSA-2001:162-04] Updated namazu packages are available</ref>
      <ref source="REDHAT" url="http://marc.info/?l=bugtraq&amp;m=101060476404565&amp;w=2">RHSA-2001:179</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101068116016472&amp;w=2">20020109 Details on the updated namazu packages that are available</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7875">linux-namazu-css(7875)</ref>
    </refs>
    <vuln_soft>
      <prod name="namazu" vendor="namazu">
        <vers num="2.0.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1353" seq="2001-1353" published="2001-09-18" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q4/0069.html">HPSBUX0112-009</ref>
      <ref source="MISC" url="http://marc.info/?l=lprng&amp;m=100083210910857&amp;w=2">http://marc.info/?l=lprng&amp;m=100083210910857&amp;w=2</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-112.html">RHSA-2001:112</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-138.html" adv="1" patch="1">RHSA-2001:138</ref>
    </refs>
    <vuln_soft>
      <prod name="ghostscript" vendor="aladdin_enterprises">
        <vers num="6.51" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1354" seq="2001-1354" published="2001-07-20" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/198293" adv="1">20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflows</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3075" adv="1">3075</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6866">netwin-nwauth-weak-encryption(6866)</ref>
    </refs>
    <vuln_soft>
      <prod name="dmail" vendor="netwin">
        <vers num="2.5d"/>
        <vers num="2.7"/>
        <vers num="2.7q"/>
        <vers num="2.7r"/>
        <vers num="2.8e"/>
        <vers num="2.8f"/>
        <vers num="2.8g"/>
        <vers num="2.8h"/>
        <vers num="2.8i"/>
      </prod>
      <prod name="surgeftp" vendor="netwin">
        <vers num="1.0b"/>
        <vers num="2.0a"/>
        <vers num="2.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1355" seq="2001-1355" published="2001-07-20" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/198293" adv="1">20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflows</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3077" adv="1">3077</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6865">netwin-nwauth-bo(6865)</ref>
    </refs>
    <vuln_soft>
      <prod name="dmail" vendor="netwin">
        <vers num="2.5d"/>
        <vers num="2.7"/>
        <vers num="2.7q"/>
        <vers num="2.7r"/>
        <vers num="2.8e"/>
        <vers num="2.8f"/>
        <vers num="2.8g"/>
        <vers num="2.8h"/>
        <vers num="2.8i"/>
      </prod>
      <prod name="surgeftp" vendor="netwin">
        <vers num="1.0b"/>
        <vers num="2.0a"/>
        <vers num="2.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1356" seq="2001-1356" published="2001-08-04" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/201951" adv="1">20010804 SurgeFTP admin account bruteforcable</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6961.php" adv="1">surgeftp-weak-password-encryption(6961)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3157" adv="1">3157</ref>
    </refs>
    <vuln_soft>
      <prod name="surgeftp" vendor="netwin">
        <vers num="2.0a"/>
        <vers num="2.0b"/>
        <vers num="2.0c"/>
        <vers num="2.0d"/>
        <vers num="2.0e"/>
        <vers num="2.0f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1357" seq="2001-1357" published="2001-02-07" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.phpheaven.net/projects/phpMyChat/changes.php3" adv="1">http://www.phpheaven.net/projects/phpMyChat/changes.php3</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmychat" vendor="phpheaven">
        <vers num="0.14.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1358" seq="2001-1358" published="2001-02-07" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.phpheaven.net/projects/phpMyChat/changes.php3" adv="1">http://www.phpheaven.net/projects/phpMyChat/changes.php3</ref>
    </refs>
    <vuln_soft>
      <prod name="phpmychat" vendor="phpheaven">
        <vers num="0.14.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1359" seq="2001-1359" published="2001-06-08" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2001-021.0.txt" adv="1">CSSA-2001-021.0</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2850" adv="1" patch="1">2850</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6672">volution-authentication-failure-access(6672)</ref>
    </refs>
    <vuln_soft>
      <prod name="volution" vendor="caldera">
        <vers num="1.0"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1360" seq="2001-1360" published="2001-07-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.mostang.com/pub/sane/sane-1.0.8/sane-backends-1.0.8.tar.gz">ftp://ftp.mostang.com/pub/sane/sane-1.0.8/sane-backends-1.0.8.tar.gz</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html" adv="1">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
    </refs>
    <vuln_soft>
      <prod name="sane" vendor="mostang">
        <vers num="1.0.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1361" seq="2001-1361" published="2001-07-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html" adv="1">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
      <ref source="CONFIRM" url="http://twig.screwdriver.net/file.php3?file=CHANGELOG">http://twig.screwdriver.net/file.php3?file=CHANGELOG</ref>
    </refs>
    <vuln_soft>
      <prod name="twig" vendor="twig_development_team">
        <vers num="2.7.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1362" seq="2001-1362" published="2001-07-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in the server for nPULSE before 0.53p4.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html" adv="1">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
      <ref source="CONFIRM" url="http://freshmeat.net/releases/51981/" adv="1">http://freshmeat.net/releases/51981/</ref>
    </refs>
    <vuln_soft>
      <prod name="npulse" vendor="horsburgh">
        <vers num="0.53p4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1363" seq="2001-1363" published="2001-07-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
      <ref source="CONFIRM" url="http://phpwebsite.appstate.edu/downloads/0.7.9/phpWebSite-en-0.7.9.tar.gz">http://phpwebsite.appstate.edu/downloads/0.7.9/phpWebSite-en-0.7.9.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod name="phpwebsite" vendor="phpwebsite_development_team">
        <vers num="0.7.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1364" seq="2001-1364" published="2001-07-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in autodns.pl for AutoDNS before 0.0.4 related to domain names that are not fully qualified.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.earth.li/pub/projectpurple/autodns-0.0.4.tar.gz">ftp://ftp.earth.li/pub/projectpurple/autodns-0.0.4.tar.gz</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
    </refs>
    <vuln_soft>
      <prod name="autodns" vendor="project_purple">
        <vers num="0.0.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1365" seq="2001-1365" published="2001-07-19" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Vulnerability in IntraGnat before 1.4.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0011.html">http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0011.html</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html" adv="1">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
    </refs>
    <vuln_soft>
      <prod name="intragnat" vendor="osi_codes_inc.">
        <vers num="1.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1366" seq="2001-1366" published="2001-07-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">netscript before 1.6.3 parses dynamic variables, which could allow remote attackers to alter program behavior or obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html" adv="1">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
      <ref source="CONFIRM" url="http://netscript.sourceforge.net/netscript-1.6.2.tgz">http://netscript.sourceforge.net/netscript-1.6.2.tgz</ref>
    </refs>
    <vuln_soft>
      <prod name="netscript" vendor="netscript_project">
        <vers num="1.6.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1367" seq="2001-1367" published="2001-07-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">The checkAccess function in PHPSlice 0.1.4, and all other versions between 0.1.1 and 0.1.6, does not properly verify the administrative access level, which could allow remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html" adv="1">20010719 [VulnWatch] Changelog maddness (14 various broken apps)</ref>
      <ref source="CONFIRM" url="http://phpslice.org/comments.php?aid=1031&amp;">http://phpslice.org/comments.php?aid=1031&amp;</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/9649">phpslice-checkaccess-function-privileges(9649)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpslice" vendor="phpslice">
        <vers num="0.1.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1368" seq="2001-1368" published="2001-06-11" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q2/0059.html" adv="1">HPSBUX0106-152</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6697">hp-virtualvault-iws-corrupt-data(6697)</ref>
    </refs>
    <vuln_soft>
      <prod name="iplanet_web_server" vendor="iplanet">
        <vers num="4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1369" seq="2001-1369" published="2001-09-10" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Leon J Breedt pam-pgsql before 0.5.2 allows remote attackers to execute arbitrary SQL code and bypass authentication or modify user account records by injecting SQL statements into user or password fields.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:14.pam-pgsql.asc">FreeBSD-SA-02:14</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7110.php" adv="1" patch="1">postgresql-pam-authentication-module(7110)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3319">3319</ref>
    </refs>
    <vuln_soft>
      <prod name="pam-pgsql" vendor="leon_j_breedt">
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1370" seq="2001-1370" published="2001-07-21" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and earlier, IMP before 2.2.6, and other packages that use PHPLib.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-027.0.txt">CSSA-2001-027.0</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000410">CLA-2001:410</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99616122712122&amp;w=2">20010726 TSLSA-2001-0014 - PHPLib</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/198495">20010721 IMP 2.2.6 (SECURITY) released</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-073" adv="1" patch="1">DSA-073</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6892.php" adv="1">phplib-script-execution(6892)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/198768" adv="1">20010722 [SEC] Hole in PHPLib 7.2 prepend.php3</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3079" adv="1" patch="1">3079</ref>
    </refs>
    <vuln_soft>
      <prod name="phplib" vendor="phplib_team">
        <vers num="7.2"/>
        <vers num="7.2.1"/>
        <vers num="7.2b"/>
        <vers num="7.2c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1371" seq="2001-1371" published="2002-02-06" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101301813117562&amp;w=2">20020206 Hackproofing Oracle Application Server paper</ref>
      <ref source="CONFIRM" url="http://technet.oracle.com/deploy/security/pdf/ias_soap_alert.pdf">http://technet.oracle.com/deploy/security/pdf/ias_soap_alert.pdf</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2002-08.html" adv="1" patch="1">CA-2002-08</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8449.php">oracle-appserver-soap-components(8449)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/736923" adv="1">VU#736923</ref>
      <ref source="MISC" url="http://www.nextgenss.com/papers/hpoas.pdf">http://www.nextgenss.com/papers/hpoas.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/4289" adv="1" patch="1">4289</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1372" seq="2001-1372" published="2002-02-06" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100074087824021&amp;w=2">20010917 Yet another path disclosure vulnerability</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100119633925473&amp;w=2">20010921 Response to "Path disclosure vulnerability in Oracle 9i and 8i</ref>
      <ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/jspexecute_alert.pdf">http://otn.oracle.com/deploy/security/pdf/jspexecute_alert.pdf</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2002-08.html" adv="1">CA-2002-08</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/278971">VU#278971</ref>
      <ref source="MISC" url="http://www.nii.co.in/research.html">http://www.nii.co.in/research.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3341" adv="1" patch="1">3341</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7135">oracle-jsp-reveal-path(7135)</ref>
    </refs>
    <vuln_soft>
      <prod name="application_server" vendor="oracle">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1373" seq="2001-1373" published="2001-07-18" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">MailSafe in Zone Labs ZoneAlarm 2.6 and earlier and ZoneAlarm Pro 2.6 and 2.4 does not block prohibited file types with long file names, which allows remote attackers to send potentially dangerous attachments.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197681">20010718 ZoneAlarm Pro</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3055" adv="1">3055</ref>
      <ref source="CONFIRM" url="http://www.zonelabs.com/products/zap/rel_history.html#2.6.362">http://www.zonelabs.com/products/zap/rel_history.html#2.6.362</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6877">zonealarm-bypass-mailsafe(6877)</ref>
    </refs>
    <vuln_soft>
      <prod name="zonealarm" vendor="zonelabs">
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4" edition=":pro"/>
        <vers num="2.5"/>
        <vers num="2.6" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1374" seq="2001-1374" published="2001-07-19" modified="2017-10-09" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000409">CLA-2001:409</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:060">MDKSA-2002:060</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-148.html">RHSA-2002:148</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3074" adv="1" patch="1">3074</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=22187">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=22187</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28224">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28224</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6870">expect-insecure-library-search(6870)</ref>
    </refs>
    <vuln_soft>
      <prod name="expect" vendor="don_libes">
        <vers num="0"/>
        <vers num="1"/>
        <vers num="2"/>
        <vers num="3"/>
        <vers num="4"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.6"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
        <vers num="5.9"/>
        <vers num="5.10"/>
        <vers num="5.11"/>
        <vers num="5.12"/>
        <vers num="5.13"/>
        <vers num="5.14"/>
        <vers num="5.15"/>
        <vers num="5.16"/>
        <vers num="5.17"/>
        <vers num="5.18"/>
        <vers num="5.19"/>
        <vers num="5.20"/>
        <vers num="5.21"/>
        <vers num="5.22"/>
        <vers num="5.23"/>
        <vers num="5.24"/>
        <vers num="5.25"/>
        <vers num="5.26"/>
        <vers num="5.27"/>
        <vers num="5.28"/>
        <vers num="5.29"/>
        <vers num="5.30"/>
        <vers num="5.31"/>
      </prod>
      <prod name="linux" vendor="conectiva">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1375" seq="2001-1375" published="2001-07-19" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000409">CLA-2001:409</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6869.php" adv="1" patch="1">tcltk-insecure-library-search(6869)</ref>
      <ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:060">MDKSA-2002:060</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-148.html">RHSA-2002:148</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3073" adv="1" patch="1">3073</ref>
      <ref source="CONFIRM" url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28226">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=28226</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="conectiva">
        <vers num="6.0"/>
        <vers num="7.0"/>
      </prod>
      <prod name="linux" vendor="redhat">
        <vers num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1376" seq="2001-1376" published="2002-03-04" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2002-q2/0362.html">SuSE-SA:2002:013</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000466">CLA-2002:466</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101537153021792&amp;w=2">20020305 SECURITY.NNOV: few vulnerabilities in multiple RADIUS implementations</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/239784" adv="1">20011113 More problems with RADIUS (protocol and implementations)</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2002-06.html" adv="1" patch="1">CA-2002-06</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/589523">VU#589523</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-030.html">RHSA-2002:030</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3530" adv="1" patch="1">3530</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7534">radius-message-digest-bo(7534)</ref>
    </refs>
    <vuln_soft>
      <prod name="radius" vendor="ascend">
        <vers num="1.16"/>
      </prod>
      <prod name="freeradius" vendor="freeradius">
        <vers num="0.2"/>
        <vers num="0.3"/>
      </prod>
      <prod name="radius" vendor="gnu">
        <vers num="0.92.1"/>
        <vers num="0.93"/>
        <vers num="0.94"/>
        <vers num="0.95"/>
      </prod>
      <prod name="icradius" vendor="icradius">
        <vers num="0.14"/>
        <vers num="0.15"/>
        <vers num="0.16"/>
        <vers num="0.17"/>
        <vers num="0.17b"/>
        <vers num="0.18"/>
        <vers num="0.18.1"/>
      </prod>
      <prod name="radius" vendor="livingston">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
      <prod name="radius" vendor="lucent">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
      <prod name="radius" vendor="miquel_van_smoorenburg_cistron">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6_.0"/>
      </prod>
      <prod name="openradius" vendor="openradius">
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
      </prod>
      <prod name="radiusclient" vendor="radiusclient">
        <vers num="0.3.1"/>
      </prod>
      <prod name="xtradius" vendor="xtradius">
        <vers num="1.1_pre1"/>
      </prod>
      <prod name="yard_radius" vendor="yard_radius">
        <vers num="1.0.17"/>
        <vers num="1.0.18"/>
        <vers num="1.0.19"/>
        <vers num="1.0_pre13"/>
        <vers num="1.0_pre14"/>
        <vers num="1.0_pre15"/>
      </prod>
      <prod name="yard_radius" vendor="yard_radius_project">
        <vers num="1.0.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1377" seq="2001-1377" published="2002-03-04" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:02.asc">FreeBSD-SN-02:02</ref>
      <ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2002-q2/0362.html">SuSE-SA:2002:013</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000466">CLA-2002:466</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101537153021792&amp;w=2">20020305 SECURITY.NNOV: few vulnerabilities in multiple RADIUS implementations</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2002-06.html" adv="1" patch="1">CA-2002-06</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8354.php" adv="1" patch="1">radius-vendor-attribute-dos(8354)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/936683" adv="1" patch="1">VU#936683</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2002-030.html">RHSA-2002:030</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/4230" adv="1" patch="1">4230</ref>
    </refs>
    <vuln_soft>
      <prod name="freeradius" vendor="freeradius">
        <vers num="0.2"/>
        <vers num="0.3"/>
      </prod>
      <prod name="radius" vendor="gnu">
        <vers num="0.92.1"/>
        <vers num="0.93"/>
        <vers num="0.94"/>
        <vers num="0.95"/>
      </prod>
      <prod name="icradius" vendor="icradius">
        <vers num="0.14"/>
        <vers num="0.15"/>
        <vers num="0.16"/>
        <vers num="0.17"/>
        <vers num="0.17b"/>
        <vers num="0.18"/>
        <vers num="0.18.1"/>
      </prod>
      <prod name="radius" vendor="livingston">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
      <prod name="radius" vendor="lucent">
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.1"/>
      </prod>
      <prod name="radius" vendor="miquel_van_smoorenburg_cistron">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6_.0"/>
      </prod>
      <prod name="openradius" vendor="openradius">
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
      </prod>
      <prod name="radiusclient" vendor="radiusclient">
        <vers num="0.3.1"/>
      </prod>
      <prod name="xtradius" vendor="xtradius">
        <vers num="1.1_pre1"/>
        <vers num="1.1_pre2"/>
      </prod>
      <prod name="yard_radius" vendor="yard_radius">
        <vers num="1.0.17"/>
        <vers num="1.0.18"/>
        <vers num="1.0.19"/>
        <vers num="1.0_pre13"/>
        <vers num="1.0_pre14"/>
        <vers num="1.0_pre15"/>
      </prod>
      <prod name="yard_radius" vendor="yard_radius_project">
        <vers num="1.0.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1378" seq="2001-1378" published="2001-09-06" modified="2011-02-16" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://lists.ccil.org/pipermail/fetchmail-announce/2001-March/000015.html">http://lists.ccil.org/pipermail/fetchmail-announce/2001-March/000015.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-103.html" patch="1">RHSA-2001:103</ref>
    </refs>
    <vuln_soft>
      <prod name="fetchmail" vendor="fetchmail">
        <vers num="4.5.1"/>
        <vers num="4.5.2"/>
        <vers num="4.5.3"/>
        <vers num="4.5.4"/>
        <vers num="4.5.5"/>
        <vers num="4.5.6"/>
        <vers num="4.5.7"/>
        <vers num="4.5.8"/>
        <vers num="4.6.0"/>
        <vers num="4.6.1"/>
        <vers num="4.6.2"/>
        <vers num="4.6.3"/>
        <vers num="4.6.4"/>
        <vers num="4.6.5"/>
        <vers num="4.6.6"/>
        <vers num="4.6.7"/>
        <vers num="4.6.8"/>
        <vers num="4.6.9"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.7.3"/>
        <vers num="4.7.4"/>
        <vers num="4.7.5"/>
        <vers num="4.7.6"/>
        <vers num="4.7.7"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.1.0"/>
        <vers num="5.1.4"/>
        <vers num="5.2.0"/>
        <vers num="5.2.1"/>
        <vers num="5.2.3"/>
        <vers num="5.2.4"/>
        <vers num="5.2.7"/>
        <vers num="5.2.8"/>
        <vers num="5.3.0"/>
        <vers num="5.3.1"/>
        <vers num="5.3.3"/>
        <vers num="5.3.8"/>
        <vers num="5.4.0"/>
        <vers num="5.4.3"/>
        <vers num="5.4.4"/>
        <vers num="5.4.5"/>
        <vers num="5.5.0"/>
        <vers num="5.5.2"/>
        <vers num="5.5.3"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.6.0"/>
        <vers num="5.7.0"/>
        <vers num="5.7.2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1379" seq="2001-1379" published="2001-08-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:03.mod_auth_pgsql.asc">FreeBSD-SA-02:03</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0040.html">20010829 [VulnWatch] RUS-CERT Advisory 2001-08:01</ref>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000427">CLA-2001:427</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99911895901812&amp;w=2">20010829 RUS-CERT Advisory 2001-08:01</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-124.html">RHSA-2001:124</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7054.php" adv="1" patch="1">apache-postgresql-authentication-module(7054)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3251">3251</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3253">3253</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7059">apache-postgresqlsys-authentication-module(7059)</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_auth_pgsql" vendor="guiseppe_tanzilli_and_matthias_eckermann">
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1380" seq="2001-1380" published="2001-10-18" modified="2018-05-02" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000431">CLSA-2001:431</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-034-01">IMNX-2001-70-034-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100154541809940&amp;w=2">20010926 OpenSSH Security Advisory (adv.option)</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-114.html" adv="1" patch="1">RHSA-2001:114</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-010.shtml">M-010</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/905795">VU#905795</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-081.php">MDKSA-2001:081</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3369">3369</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7179">openssh-access-control-bypass(7179)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="2.9.9" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1382" seq="2001-1382" published="2001-09-27" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage return is entered, which could allow remote attackers to determine that the countermeasure is being used.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.openwall.com/Owl/CHANGES-stable.shtml" adv="1">http://www.openwall.com/Owl/CHANGES-stable.shtml</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="2.9.9p2" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1383" seq="2001-1383" published="2001-09-26" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-110.html" adv="1" patch="1">RHSA-2001:110</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7177.php" adv="1" patch="1">linux-setserial-initscript-symlink(7177)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3367">3367</ref>
    </refs>
    <vuln_soft>
      <prod name="linux" vendor="redhat">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1384" seq="2001-1384" published="2001-10-18" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt">CSSA-2001-036.0</ref>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01">IMNX-2001-70-035-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100343090106914&amp;w=2">20011018 Flaws in recent Linux kernels</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100350685431610&amp;w=2">20011019 TSLSA-2001-0028</ref>
      <ref source="HP" url="http://online.securityfocus.com/advisories/3713">HPSBTL0112-003</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7311.php" adv="1" patch="1">linux-ptrace-race-condition(7311)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-079.php3">MDKSA-2001:079</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3">MDKSA-2001:082</ref>
      <ref source="ENGARDE" url="http://www.linuxsecurity.com/advisories/other_advisory-1650.html" adv="1" patch="1">ESA-20011019-02</ref>
      <ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_036_kernel_txt.html">SuSE-SA:2001:036</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-129.html">RHSA-2001:129</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-130.html">RHSA-2001:130</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3447">3447</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.2.5"/>
        <vers num="2.2.6"/>
        <vers num="2.2.7"/>
        <vers num="2.2.8"/>
        <vers num="2.2.9"/>
        <vers num="2.2.10"/>
        <vers num="2.2.11"/>
        <vers num="2.2.12"/>
        <vers num="2.2.13"/>
        <vers num="2.2.14"/>
        <vers num="2.2.15"/>
        <vers num="2.2.16"/>
        <vers num="2.2.17"/>
        <vers num="2.2.18"/>
        <vers num="2.2.19"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1385" seq="2001-1385" published="2001-01-12" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000373">CLA-2001:373</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=97957961212852">20010112 PHP Security Advisory - Apache Module bugs</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-020">DSA-020</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/5939.php" adv="1" patch="1">php-view-source-code(5939)</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-013.php3">MDKSA-2001:013</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-136.html" patch="1">RHSA-2000:136</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2205">2205</ref>
    </refs>
    <vuln_soft>
      <prod name="php" vendor="php">
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1386" seq="2001-1386" published="2001-07-01" modified="2017-10-09" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/194442">20010701 WFTPD v3.00 R5 Directory Traversal</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2957" adv="1" patch="1">2957</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6760">ftp-lnk-directory-traversal(6760)</ref>
    </refs>
    <vuln_soft>
      <prod name="wftpd" vendor="texas_imperial_software">
        <vers num="2.4.1"/>
        <vers num="2.4.1_rc11"/>
        <vers num="2.4.1_rc12"/>
        <vers num="2.40"/>
        <vers num="2.41_rc14" edition=":pro"/>
        <vers num="3.0" edition=":pro"/>
        <vers num="3.0_0r3"/>
        <vers num="3.0_0r4" edition=":pro"/>
        <vers num="3.0_0r5" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1387" seq="2001-1387" published="2001-11-05" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=50500">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=50500</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-144.html" adv="1">RHSA-2001:144</ref>
    </refs>
    <vuln_soft>
      <prod name="iptables" vendor="netfilter_core_team">
        <vers num="1.1.2"/>
        <vers num="1.2"/>
        <vers num="1.2.1a"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1388" seq="2001-1388" published="2001-11-05" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=53325">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=53325</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-144.html" adv="1">RHSA-2001:144</ref>
    </refs>
    <vuln_soft>
      <prod name="iptables" vendor="netfilter_core_team">
        <vers num="1.1.2"/>
        <vers num="1.2"/>
        <vers num="1.2.1a"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1389" seq="2001-1389" published="2001-08-29" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-033-01">IMNX-2001-70-033-01</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99913751525583&amp;w=2">20010830 xinetd 2.3.0 audit status</ref>
      <ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2001-109.html" adv="1" patch="1">RHSA-2001:109</ref>
      <ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-076.php3" adv="1">MDKSA-2001:076</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3257">3257</ref>
    </refs>
    <vuln_soft>
      <prod name="xinetd" vendor="xinetd">
        <vers num="2.1.8.8"/>
        <vers num="2.1.8.8_pre3"/>
        <vers num="2.1.8.9_pre1"/>
        <vers num="2.1.8.9_pre2"/>
        <vers num="2.1.8.9_pre3"/>
        <vers num="2.1.8.9_pre5"/>
        <vers num="2.1.8.9_pre7"/>
        <vers num="2.1.8.9_pre8"/>
        <vers num="2.1.8.9_pre9"/>
        <vers num="2.1.8.9_pre10"/>
        <vers num="2.1.8.9_pre11"/>
        <vers num="2.1.8.9_pre12"/>
        <vers num="2.1.8.9_pre13"/>
        <vers num="2.1.8.9_pre14"/>
        <vers num="2.1.8.9_pre15"/>
        <vers num="2.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1390" seq="2001-1390" published="2001-04-17" modified="2016-12-07" severity="Medium" CVSS_version="2.0" CVSS_score="6.2" CVSS_base_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:18</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1391" seq="2001-1391" published="2001-04-17" modified="2017-10-09" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1">RHSA-2001:047</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11162">linux-cpia-memory-overwrite(11162)</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1392" seq="2001-1392" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1393" seq="2001-1393" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1394" seq="2001-1394" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1395" seq="2001-1395" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1396" seq="2001-1396" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1397" seq="2001-1397" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1398" seq="2001-1398" published="2001-04-17" modified="2016-12-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Masquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1399" seq="2001-1399" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory, aka "User access asm bug on x86."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1400" seq="2001-1400" published="2001-04-17" modified="2016-12-07" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="IMMUNIX" url="http://marc.info/?l=bugtraq&amp;m=98575345009963&amp;w=2">IMNX-2001-70-010-01</ref>
      <ref source="CALDERA" url="http://marc.info/?l=bugtraq&amp;m=98637996127004&amp;w=2">CSSA-2001-012.0</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98653252326445&amp;w=2">20010405 Trustix Security Advisory #2001-0003 - kernel</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=98684172109474&amp;w=2">20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels</ref>
      <ref source="MANDRAKE" url="http://marc.info/?l=bugtraq&amp;m=98759029811377&amp;w=2">MDKSA-2001:037</ref>
      <ref source="CONECTIVA" url="http://marc.info/?l=bugtraq&amp;m=98775114228203&amp;w=2">CLA-2001:394</ref>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=99013830726309&amp;w=2">SuSE-SA:2001:018</ref>
      <ref source="CONFIRM" url="http://www.linux.org.uk/VERSION/relnotes.2219.html">http://www.linux.org.uk/VERSION/relnotes.2219.html</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-047.html" adv="1" patch="1">RHSA-2001:047</ref>
      <ref source="DEBIAN" url="https://www.debian.org/security/2001/dsa-047">DSA-047</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1401" seq="2001-1401" published="2001-09-10" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=39524">http://bugzilla.mozilla.org/show_bug.cgi?id=39524</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=39526">http://bugzilla.mozilla.org/show_bug.cgi?id=39526</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=39527">http://bugzilla.mozilla.org/show_bug.cgi?id=39527</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=39531">http://bugzilla.mozilla.org/show_bug.cgi?id=39531</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=39533">http://bugzilla.mozilla.org/show_bug.cgi?id=39533</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=70189">http://bugzilla.mozilla.org/show_bug.cgi?id=70189</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=82781">http://bugzilla.mozilla.org/show_bug.cgi?id=82781</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99912899900567">20010829 Security Advisory for Bugzilla v2.13 and older</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-107.html" adv="1" patch="1">RHSA-2001:107</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1402" seq="2001-1402" published="2001-09-10" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in process_bug.cgi, and (6) error messages in buglist.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=38854">http://bugzilla.mozilla.org/show_bug.cgi?id=38854</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=38855">http://bugzilla.mozilla.org/show_bug.cgi?id=38855</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=38859">http://bugzilla.mozilla.org/show_bug.cgi?id=38859</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=39536">http://bugzilla.mozilla.org/show_bug.cgi?id=39536</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=87701">http://bugzilla.mozilla.org/show_bug.cgi?id=87701</ref>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=95235">http://bugzilla.mozilla.org/show_bug.cgi?id=95235</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99912899900567">20010829 Security Advisory for Bugzilla v2.13 and older</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-107.html" adv="1" patch="1">RHSA-2001:107</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1403" seq="2001-1403" published="2001-09-10" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=15980">http://bugzilla.mozilla.org/show_bug.cgi?id=15980</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99912899900567">20010829 Security Advisory for Bugzilla v2.13 and older</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-107.html" adv="1" patch="1">RHSA-2001:107</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1404" seq="2001-1404" published="2001-09-10" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=74032">http://bugzilla.mozilla.org/show_bug.cgi?id=74032</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99912899900567">20010829 Security Advisory for Bugzilla v2.13 and older</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-107.html" adv="1" patch="1">RHSA-2001:107</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1405" seq="2001-1405" published="2001-09-10" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=54556">http://bugzilla.mozilla.org/show_bug.cgi?id=54556</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99912899900567">20010829 Security Advisory for Bugzilla v2.13 and older</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-107.html" adv="1" patch="1">RHSA-2001:107</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1406" seq="2001-1406" published="2001-09-10" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be as stringent.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=66235">http://bugzilla.mozilla.org/show_bug.cgi?id=66235</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99912899900567">20010829 Security Advisory for Bugzilla v2.13 and older</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10478.php">bugzilla-processbug-old-restrictions(10478)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-107.html" adv="1" patch="1">RHSA-2001:107</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1407" seq="2001-1407" published="2001-09-10" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows the user to view the bug.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://bugzilla.mozilla.org/show_bug.cgi?id=96085">http://bugzilla.mozilla.org/show_bug.cgi?id=96085</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99912899900567">20010829 Security Advisory for Bugzilla v2.13 and older</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10479.php">bugzilla-duplicate-view-restricted(10479)</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-107.html" adv="1" patch="1">RHSA-2001:107</ref>
    </refs>
    <vuln_soft>
      <prod name="bugzilla" vendor="mozilla">
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1408" seq="2001-1408" published="2001-07-05" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0092.html">20010705 Cobalt Cube Webmail directory traversal</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0245.html" adv="1">20010818 Cobalt update for my Webmail issue.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6805">cobalt-qube-directory-traversal(6805)</ref>
    </refs>
    <vuln_soft>
      <prod name="qube" vendor="cobalt">
        <vers num="3.0"/>
      </prod>
      <prod name="webmail" vendor="cobalt">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1409" seq="2001-1409" published="2003-07-24" modified="2010-05-25" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.au" adv="1" patch="1">http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.au</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-228529-1">228529</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1017429.1-1">1017429</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2003-067.html" adv="1" patch="1">RHSA-2003:067</ref>
    </refs>
    <vuln_soft>
      <prod name="xfree86_x_server" vendor="xfree86_project">
        <vers num="4.1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1410" seq="2001-1410" published="2003-08-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105820229407274&amp;w=2">20030713 IE chromeless window vulnerabilities</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=105829174431769&amp;w=2">20030715 Internet Explorer Full-Screen mode threats</ref>
      <ref source="MISC" url="http://www.doxdesk.com/personal/posts/bugtraq/20030713-ie/">http://www.doxdesk.com/personal/posts/bugtraq/20030713-ie/</ref>
      <ref source="MISC" url="http://www.guninski.com/popspoof.html">http://www.guninski.com/popspoof.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/490708">VU#490708</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/221883" adv="1">20011021 Javascript in IE may spoof the whole screen</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3469" adv="1">3469</ref>
      <ref source="MISC" url="http://www.systemintegra.com/ie-fullscreen/">http://www.systemintegra.com/ie-fullscreen/</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7313">ie-javascript-spoof-dialog(7313)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1411" seq="2001-1411" published="2003-11-17" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=100368233714229&amp;w=2">20011020 gm4 format strings on OSX</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/10174.php">macos-gm4-utility-bo(10174)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/147587" adv="1">VU#147587</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1412" seq="2001-1412" published="2003-11-17" modified="2016-10-17" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://lists.apple.com/mhonarc/security-announce/msg00038.html">http://lists.apple.com/mhonarc/security-announce/msg00038.html</ref>
      <ref source="BUGTRAQ" url="http://lists.insecure.org/lists/bugtraq/2002/Sep/0128.html" adv="1">20020915 nidump on OS X</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99953038722104&amp;w=2">20010903 Re: Possible Issue with Netinfo and Mac OS X</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1001946">1001946</ref>
      <ref source="MISC" url="http://www.securemac.com/macosxnidump.php" adv="1" patch="1">http://www.securemac.com/macosxnidump.php</ref>
      <ref source="MISC" url="http://www.securiteam.com/securityreviews/5QP032A4UU.html" adv="1">http://www.securiteam.com/securityreviews/5QP032A4UU.html</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.4.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1413" seq="2001-1413" published="2004-12-23" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://seclists.org/lists/vuln-dev/2001/Nov/0202.html">20010621 New bugs, old bugs</ref>
      <ref source="GENTOO" url="http://security.gentoo.org/glsa/glsa-200410-08.xml" adv="1" patch="1">GLSA-200410-08</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/176363" adv="1">VU#176363</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2004-536.html" adv="1" patch="1">RHSA-2004:536</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10619">ncompress-filename-bo(10619)</ref>
    </refs>
    <vuln_soft>
      <prod name="ncompress" vendor="ncompress">
        <vers num="4.2.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1414" seq="2001-1414" published="2001-10-09" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Basic Security Module (BSM) for Solaris 2.5.1, 2.6, 7, and 8 does not log anonymous FTP access, which allows remote attackers to hide their activities, possibly when certain BSM audit files are not present under the FTP root.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-40521-1" adv="1">40521</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/7396">7396</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/11841">solaris-bsm-no-audit(11841)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1415" seq="2001-1415" published="2001-11-13" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/016_recover.patch" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.9/common/016_recover.patch</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/191675">VU#191675</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10149">bsd-virecover-delete-files(10149)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.9"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1416" seq="2001-1416" published="2001-01-18" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.1" CVSS_base_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/541384">VU#541384</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-56TPBQ">http://www.kb.cert.org/vuls/id/JARL-56TPBQ</ref>
      <ref source="MISC" url="http://www.windowsitpro.com/Articles/Index.cfm?ArticleID=19811&amp;DisplayTab=Article">http://www.windowsitpro.com/Articles/Index.cfm?ArticleID=19811&amp;DisplayTab=Article</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.4a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1417" seq="2001-1417" published="2001-10-06" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/710347">VU#710347</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-56TQEN">http://www.kb.cert.org/vuls/id/JARL-56TQEN</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218920">20011006 AIM Exploits</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247707">20011230 Windows AIM Client Exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3408">3408</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7255">aim-large-buddyicon-dos(7255)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1418" seq="2001-1418" published="2001-10-06" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fixed in Win AIM Beta 4.8.2540 posted Nov. 19th.</sol>
    </sols>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/990451">VU#990451</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-569M8X">http://www.kb.cert.org/vuls/id/JARL-569M8X</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218920">20011006 AIM Exploits</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10686">aim-wav-file-dos(10686)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1419" seq="2001-1419" published="2001-10-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "&lt;!--" HTML comments.</descript>
      <descript source="nvd">Fixed in Win AIM Beta 4.8.2540 posted Nov. 19th.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0014.html">20011002 AIM 0day DoS</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/507771" adv="1">VU#507771</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-56TPTN">http://www.kb.cert.org/vuls/id/JARL-56TPTN</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247707">20011230 Windows AIM Client Exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3398" adv="1">3398</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7233">aim-html-comments-dos(7233)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.3"/>
        <vers num="4.3.2229"/>
        <vers num="4.4"/>
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="4.7.2480"/>
      </prod>
      <prod name="trillian" vendor="cerulean_studios">
        <vers num="0.6351"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1420" seq="2001-1420" published="2005-05-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/972499">VU#972499</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-569MEK">http://www.kb.cert.org/vuls/id/JARL-569MEK</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218920">20011006 AIM Exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3407">3407</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7254">aim-long-filename-dos(7254)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1421" seq="2001-1421" published="2001-10-06" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/530299">VU#530299</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-569MD7">http://www.kb.cert.org/vuls/id/JARL-569MD7</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/218920">20011006 AIM Exploits</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/247707">20011230 Windows AIM Client Exploits</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3756">3756</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7757">aim-multiple-fonts-dos(7757)</ref>
    </refs>
    <vuln_soft>
      <prod name="instant_messenger" vendor="aol">
        <vers num="4.7" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1422" seq="2001-1422" published="2001-01-23" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/303080" adv="1">VU#303080</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2275" adv="1">2275</ref>
      <ref source="MISC" url="http://www1.corest.com/common/showdoc.php?idxseccion=10&amp;idx=117" adv="1">http://www1.corest.com/common/showdoc.php?idxseccion=10&amp;idx=117</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/5992">vnc-weak-authentication(5992)</ref>
    </refs>
    <vuln_soft>
      <prod name="winvnc" vendor="att">
        <vers num="3.3.3" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1423" seq="2001-1423" published="2001-10-10" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Advanced Poll before 1.61, when using a flat file database, allows remote attackers to gain privileges by setting the logged_in parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1002516">1002516</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/140723">VU#140723</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7861">advancedpoll-php-admin-access(7861)</ref>
    </refs>
    <vuln_soft>
      <prod name="advanced_poll" vendor="advanced_poll">
        <vers num="1.6" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1424" seq="2001-1424" published="2001-04-10" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Alcatel Speed Touch ADSL modem running firmware KHDSAA.108, KHDSAA.132, KHDSBA.133, and KHDSAA.134 has a blank default password, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html">http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-08.html">CA-2001-08</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/212088">VU#212088</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/175229">20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2568">2568</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6335">alcatel-blank-password(6335)</ref>
    </refs>
    <vuln_soft>
      <prod name="speed_touch_home" vendor="alcatel">
        <vers num="khdsaa.108"/>
        <vers num="khdsaa.132"/>
        <vers num="khdsaa.133"/>
        <vers num="khdsaa.134"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1425" seq="2001-1425" published="2001-04-10" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The challenge-response authentication of the EXPERT user for Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 allows remote attackers to gain privileges by directly computing the response based on information that is provided by the device during login.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html">http://security.sdsc.edu/self-help/alcatel/alcatel-bugs.html</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-08.html">CA-2001-08</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/243592">VU#243592</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/175229">20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2568" adv="1">2568</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6354">alcatel-expert-account(6354)</ref>
    </refs>
    <vuln_soft>
      <prod name="speed_touch_home" vendor="alcatel">
        <vers num="khdsaa.108"/>
        <vers num="khdsaa.132"/>
        <vers num="khdsaa.133"/>
        <vers num="khdsaa.134"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1426" seq="2001-1426" published="2001-04-10" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Alcatel Speed Touch running firmware KHDSAA.108 and KHDSAA.132 through KHDSAA.134 has a TFTP server running without a password, which allows remote attackers to change firmware versions or the device's configurations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-08.html">CA-2001-08</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/490344">VU#490344</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/175229">20010410 multiple vulnerabilities in Alcatel Speed Touch DSL modems</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2566" patch="1">2566</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6336">alcatel-tftp-lan-access(6336)</ref>
    </refs>
    <vuln_soft>
      <prod name="speed_touch_home" vendor="alcatel">
        <vers num="khdsaa.108"/>
        <vers num="khdsaa.132"/>
        <vers num="khdsaa.133"/>
        <vers num="khdsaa.134"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1427" seq="2001-1427" published="2001-07-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in ColdFusion Server 2.0 through 4.5.1 SP2 allows remote attackers to overwrite templates with zero byte files via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/321475" patch="1">VU#321475</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/devnet/security/security_zone/mpsb01-07.html" patch="1">http://www.macromedia.com/devnet/security/security_zone/mpsb01-07.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3023" patch="1">3023</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6840">coldfusion-overwrite-template(6840)</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="macromedia">
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.5"/>
        <vers num="4.5.1" edition="sp1"/>
        <vers num="4.5.1" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1428" seq="2001-1428" published="2001-05-24" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/426459">VU#426459</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/46219">VU#461219</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/186418">20010524 IPC@Chip Security</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2769">2769</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2770" adv="1">2770</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6597">ipcchip-ftp-default-passwords(6597)</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6598">ipcchip-telnet-default-password(6598)</ref>
    </refs>
    <vuln_soft>
      <prod name="ipc_at_chip_embedded-webserver" vendor="beck_ipc_gmbh">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1429" seq="2001-1429" published="2001-11-12" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in mcedit in Midnight Commander 4.5.1 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted text file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/203203">VU#203203</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10630">midnight-commander-mcedit-bo(10630)</ref>
    </refs>
    <vuln_soft>
      <prod name="midnight_commander" vendor="midnight_commander">
        <vers num="4.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1430" seq="2001-1430" published="2001-06-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/557136">VU#557136</ref>
      <ref source="CONFIRM" url="http://www.kb.cert.org/vuls/id/JARL-4ZTKY9">http://www.kb.cert.org/vuls/id/JARL-4ZTKY9</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/196083">20010711 cayman strikes again</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3017">3017</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6841">cayman-dsl-insecure-permissions(6841)</ref>
    </refs>
    <vuln_soft>
      <prod name="3220-h_dsl_router" vendor="cayman">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1431" seq="2001-1431" published="2001-10-08" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258731">VU#258731</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8293">nokia-cp-packet-retransmission(8293)</ref>
    </refs>
    <vuln_soft>
      <prod name="firewall-1" vendor="checkpoint">
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
        <vers num="4.1" edition="sp5"/>
      </prod>
      <prod name="vpn-1" vendor="checkpoint">
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
      </prod>
      <prod name="firewall_appliance" vendor="nokia">
        <vers num="ipso_3.3"/>
        <vers num="ipso_3.4"/>
        <vers num="ipso_3.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1432" seq="2001-1432" published="2001-12-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.8" CVSS_base_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0085.html">20011229 Remote Root Hole in Cherokee Webserver</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/464827">VU#464827</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3772">3772</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7799">cherokee-http-directory-traversal(7799)</ref>
    </refs>
    <vuln_soft>
      <prod name="cherokee_httpd" vendor="cherokee">
        <vers num="0.1"/>
        <vers num="0.1.5"/>
        <vers num="0.1.6"/>
        <vers num="0.2"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
        <vers num="0.2.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1433" seq="2001-1433" published="2001-12-29" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0085.html">20011229 Remote Root Hole in Cherokee Webserver</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/245795">VU#245795</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3771" patch="1">3771</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7797">cherokee-http-insecure-privileges(7797)</ref>
    </refs>
    <vuln_soft>
      <prod name="cherokee_httpd" vendor="cherokee">
        <vers num="0.1"/>
        <vers num="0.1.5"/>
        <vers num="0.1.6"/>
        <vers num="0.2"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1434" seq="2001-1434" published="2001-02-28" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CISCO" url="http://www.cisco.com/warp/public/707/ios-snmp-community-vulns-pub.shtml" adv="1">20010228 Cisco IOS Software Multiple SNMP Community String Vulnerabilities</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/848944">VU#848944</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6178">cisco-ios-snmp-server-community(6178)</ref>
    </refs>
    <vuln_soft>
      <prod name="ios" vendor="cisco">
        <vers num="12.0"/>
        <vers num="12.0(1)"/>
        <vers num="12.0(1)w"/>
        <vers num="12.0(1)xa3"/>
        <vers num="12.0(1)xb"/>
        <vers num="12.0(1)xe"/>
        <vers num="12.0(2)"/>
        <vers num="12.0(2)xc"/>
        <vers num="12.0(2)xd"/>
        <vers num="12.0(2)xe"/>
        <vers num="12.0(2)xf"/>
        <vers num="12.0(2)xg"/>
        <vers num="12.0(2b)"/>
        <vers num="12.0(3)"/>
        <vers num="12.0(3)t2"/>
        <vers num="12.0(3d)"/>
        <vers num="12.0(4)s"/>
        <vers num="12.0(4)t"/>
        <vers num="12.0(4)xe"/>
        <vers num="12.0(4)xe1"/>
        <vers num="12.0(4)xm"/>
        <vers num="12.0(4)xm1"/>
        <vers num="12.0(5)t"/>
        <vers num="12.0(5)t1"/>
        <vers num="12.0(5)wc"/>
        <vers num="12.0(5)wc2"/>
        <vers num="12.0(5)wc2b"/>
        <vers num="12.0(5)wc3"/>
        <vers num="12.0(5)wc3b"/>
        <vers num="12.0(5)wx"/>
        <vers num="12.0(5)xe"/>
        <vers num="12.0(5)xk"/>
        <vers num="12.0(5)xk2"/>
        <vers num="12.0(5)xn"/>
        <vers num="12.0(5)xn1"/>
        <vers num="12.0(5)xs"/>
        <vers num="12.0(5)xu"/>
        <vers num="12.0(5)yb4"/>
        <vers num="12.0(5.1)xp"/>
        <vers num="12.0(5.2)xu"/>
        <vers num="12.0(5.3)wc1"/>
        <vers num="12.0(5.4)wc1"/>
        <vers num="12.0(6b)"/>
        <vers num="12.0(7)db2"/>
        <vers num="12.0(7)dc1"/>
        <vers num="12.0(7)s1"/>
        <vers num="12.0(7)sc"/>
        <vers num="12.0(7)t"/>
        <vers num="12.0(7)t2"/>
        <vers num="12.0(7)wx5(15a)"/>
        <vers num="12.0(7)xe"/>
        <vers num="12.0(7)xe2"/>
        <vers num="12.0(7)xf"/>
        <vers num="12.0(7)xf1"/>
        <vers num="12.0(7)xk"/>
        <vers num="12.0(7)xk3"/>
        <vers num="12.0(7)xv"/>
        <vers num="12.0(7.4)s"/>
        <vers num="12.0(7a)"/>
        <vers num="12.0(8)"/>
        <vers num="12.0(8)s1"/>
        <vers num="12.0(8.0.2)s"/>
        <vers num="12.0(8.3)sc"/>
        <vers num="12.0(8a)"/>
        <vers num="12.0(9)"/>
        <vers num="12.0(9)s"/>
        <vers num="12.0(9)s8"/>
        <vers num="12.0(9a)"/>
        <vers num="12.0(10)s7"/>
        <vers num="12.0(10)w5"/>
        <vers num="12.0(10)w5(18f)"/>
        <vers num="12.0(10)w5(18g)"/>
        <vers num="12.0(10a)"/>
        <vers num="12.0(11)s6"/>
        <vers num="12.0(11)st4"/>
        <vers num="12.0(11a)"/>
        <vers num="12.0(12)s3"/>
        <vers num="12.0(12a)"/>
        <vers num="12.0(13)s6"/>
        <vers num="12.0(13)w5(19c)"/>
        <vers num="12.0(13)wt6(1)"/>
        <vers num="12.0(13a)"/>
        <vers num="12.0(14)s7"/>
        <vers num="12.0(14)st"/>
        <vers num="12.0(14)st3"/>
        <vers num="12.0(14)w5(20)"/>
        <vers num="12.0(14a)"/>
        <vers num="12.0(15)s3"/>
        <vers num="12.0(15)s6"/>
        <vers num="12.0(15a)"/>
        <vers num="12.0(16)s8"/>
        <vers num="12.0(16)sc3"/>
        <vers num="12.0(16)st1"/>
        <vers num="12.0(16)w5(21)"/>
        <vers num="12.0(16.06)s"/>
        <vers num="12.0(16a)"/>
        <vers num="12.0(17)"/>
        <vers num="12.0(17)s"/>
        <vers num="12.0(17)s4"/>
        <vers num="12.0(17)sl2"/>
        <vers num="12.0(17)sl6"/>
        <vers num="12.0(17)st1"/>
        <vers num="12.0(17)st5"/>
        <vers num="12.0(17a)"/>
        <vers num="12.0(18)s"/>
        <vers num="12.0(18)s5"/>
        <vers num="12.0(18)st1"/>
        <vers num="12.0(18)w5(22b)"/>
        <vers num="12.0(18b)"/>
        <vers num="12.0da"/>
        <vers num="12.0db"/>
        <vers num="12.0dc"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0sl"/>
        <vers num="12.0sp"/>
        <vers num="12.0st"/>
        <vers num="12.0sx"/>
        <vers num="12.0t"/>
        <vers num="12.0w5"/>
        <vers num="12.0wc"/>
        <vers num="12.0wt"/>
        <vers num="12.0wx"/>
        <vers num="12.0xa"/>
        <vers num="12.0xb"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xf"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xm"/>
        <vers num="12.0xn"/>
        <vers num="12.0xp"/>
        <vers num="12.0xq"/>
        <vers num="12.0xr"/>
        <vers num="12.0xs"/>
        <vers num="12.0xu"/>
        <vers num="12.1"/>
        <vers num="12.1(20)e"/>
        <vers num="12.1(20)e1"/>
        <vers num="12.1(20)e2"/>
        <vers num="12.1(20)ea1"/>
        <vers num="12.1(20)ec"/>
        <vers num="12.1(20)ec1"/>
        <vers num="12.1(20)ew"/>
        <vers num="12.1(20)ew1"/>
        <vers num="12.1aa"/>
        <vers num="12.1ax"/>
        <vers num="12.1ay"/>
        <vers num="12.1da"/>
        <vers num="12.1db"/>
        <vers num="12.1dc"/>
        <vers num="12.1e"/>
        <vers num="12.1ea"/>
        <vers num="12.1eb"/>
        <vers num="12.1ec"/>
        <vers num="12.1eo"/>
        <vers num="12.1eu"/>
        <vers num="12.1ev"/>
        <vers num="12.1ew"/>
        <vers num="12.1ex"/>
        <vers num="12.1ey"/>
        <vers num="12.1m"/>
        <vers num="12.1t"/>
        <vers num="12.1xa"/>
        <vers num="12.1xb"/>
        <vers num="12.1xc"/>
        <vers num="12.1xd"/>
        <vers num="12.1xe"/>
        <vers num="12.1xf"/>
        <vers num="12.1xg"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xj"/>
        <vers num="12.1xk"/>
        <vers num="12.1xl"/>
        <vers num="12.1xm"/>
        <vers num="12.1xp"/>
        <vers num="12.1xq"/>
        <vers num="12.1xr"/>
        <vers num="12.1xs"/>
        <vers num="12.1xt"/>
        <vers num="12.1xu"/>
        <vers num="12.1xv"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1yb"/>
        <vers num="12.1yc"/>
        <vers num="12.1yd"/>
        <vers num="12.1ye"/>
        <vers num="12.1yf"/>
        <vers num="12.1yh"/>
        <vers num="12.1yi"/>
        <vers num="12.1yj"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1435" seq="2001-1435" published="2001-02-23" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">inetd in Compaq Tru64 UNIX 5.1 allows attackers to cause a denial of service (network connection loss) by causing one of the services handled by inetd to core dump during startup, which causes inetd to stop accepting connections to all of its services.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/880624">VU#880624</ref>
      <ref source="COMPAQ" url="http://www.securityfocus.com/archive/1/165535">SSRT0708U</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6157">tru64-inetd-dos(6157)</ref>
    </refs>
    <vuln_soft>
      <prod name="tru64" vendor="compaq">
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1436" seq="2001-1436" published="2001-01-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier for users with physical access to conduct dictionary attacks against the device password.</descript>
    </desc>
    <sols>
      <sol source="nvd">New version DS1963S corrects problem.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a011801-1.txt" adv="1">A011801-1</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/178560" adv="1">VU#178560</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10625">ibutton-ds1991-dictionary(10625)</ref>
    </refs>
    <vuln_soft>
      <prod name="ibutton" vendor="dallas_semiconductor">
        <vers num="ds1991"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1437" seq="2001-1437" published="2001-12-01" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html">20011201 easynews 1.5 let's remote users modify database</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/597795">VU#597795</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3649">3649</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7660">easynews-php-reveal-path(7660)</ref>
    </refs>
    <vuln_soft>
      <prod name="easynews" vendor="easyscripts">
        <vers num="1.5" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1438" seq="2001-1438" published="2001-10-22" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/222739">VU#222739</ref>
      <ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/222110">20011022 PalmOS crashes receiving SMS images using Handspring VisorPhone</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10637">handspring-visor-sms-dos(10637)</ref>
    </refs>
    <vuln_soft>
      <prod name="visor" vendor="handspring">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
      </prod>
      <prod name="palm_os" vendor="palm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1439" seq="2001-1439" published="2001-02-16" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the text editor functionality in HP-UX 10.01 through 11.04 on HP9000 Series 700 and Series 800 allows local users to cause a denial of service ("system availability") via text editors such as (1) e, (2) ex, (3) vi, (4) edit, (5) view, and (6) vedit.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="AUSCERT" url="http://www.auscert.org.au/render.html?it=1176" patch="1">ESB-2001.066</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/268848" patch="1">VU#268848</ref>
      <ref source="HP" url="http://www.securityfocus.com/archive/1/163910" patch="1">HPSBUX0011-132</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6111">hp-text-editor-bo(6111)</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1440" seq="2001-1440" published="2001-12-21" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1003038">1003038</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/249491">VU#249491</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6839">6839</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY26302&amp;apar=only" adv="1">IY26302</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8269">aix-login-unauth-access(8269)</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="5.1l"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1441" seq="2001-1441" published="2001-07-02" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/archive/bugtraq/2001/07/msg00021.html">20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/270083">VU#270083</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6793">java-servlet-crosssite-scripting(6793)</ref>
    </refs>
    <vuln_soft>
      <prod name="visualage_for_java" vendor="ibm">
        <vers num="3.5" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1442" seq="2001-1442" published="2001-04-21" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument.</descript>
    </desc>
    <sols>
      <sol source="nvd">INN 2.3.0 fixes problem.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0311.html">20010418 Innfeed Buffer Overflow</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1001353">1001353</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/943536">VU#943536</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/178011" patch="1">20010418 Re: Innfeed Buffer Overflow</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2620" patch="1">2620</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6398">innfeed-c-bo(6398)</ref>
    </refs>
    <vuln_soft>
      <prod name="inn" vendor="isc">
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1443" seq="2001-1443" published="2001-08-27" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">KTH Kerberos IV and Kerberos V (Heimdal) for Telnet clients do not encrypt connections if the server does not support the requested encryption, which allows remote attackers to read communications via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://josefsson.org/ktelnet/kerberos-telnet.html">http://josefsson.org/ktelnet/kerberos-telnet.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/390280" adv="1">VU#390280</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10640">kth-kerberos-unencrypted-connection(10640)</ref>
    </refs>
    <vuln_soft>
      <prod name="kth_kerberos" vendor="kth">
        <vers num="4"/>
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1444" seq="2001-1444" published="2001-08-27" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://josefsson.org/ktelnet/kerberos-telnet.html">http://josefsson.org/ktelnet/kerberos-telnet.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/774587" adv="1">VU#774587</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10640">kth-kerberos-unencrypted-connection(10640)</ref>
    </refs>
    <vuln_soft>
      <prod name="kth_kerberos" vendor="kth">
        <vers num="4"/>
        <vers num="5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1445" seq="2001-1445" published="2001-03-01" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to R5.0.8 to resolve the problem.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/176972" adv="1">VU#176972</ref>
      <ref source="CONFIRM" url="http://www-1.ibm.com/support/docview.wss?rs=899&amp;uid=swg21085603" adv="1" patch="1">http://www-1.ibm.com/support/docview.wss?rs=899&amp;uid=swg21085603</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6591">lotus-domino-smtp-mail-relay(6591)</ref>
    </refs>
    <vuln_soft>
      <prod name="domino_mail_server" vendor="lotus">
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.2b"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1446" seq="2001-1446" published="2001-09-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files in web accessible directories.</descript>
    </desc>
    <sols>
      <sol source="nvd">It is reported that this issue is addressed in the Apple Mac OS X and Mac OS X Server release versions 10.2 and above. This is not confirmed.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0085.html">20010910 Re: More security problems in Apache on Mac OS X</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/177243" adv="1">VU#177243</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3325">3325</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7103">macos-apache-directory-disclosure(7103)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1447" seq="2001-1447" published="2001-10-17" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2) "services" menus, which causes the applications to run with root privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0121.html">20011017 Mac OS X setuid root security hole</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0130.html" adv="1">20011017 Re: Mac OS X setuid root security hole</ref>
      <ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/m-007.shtml">M-007</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/945747" patch="1">VU#945747</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3439">3439</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7303">macos-netinfo-root-privileges(7303)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1448" seq="2001-1448" published="2001-12-17" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/157795">VU#157795</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/246343">20011217 MAGIC Enterprise Multiple Vulnerabilities</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10616">magic-edeveloper-tmp-symlink(10616)</ref>
    </refs>
    <vuln_soft>
      <prod name="edeveloper" vendor="magic">
        <vers num="8.30.5" prev="1" edition=":enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1449" seq="2001-1449" published="2001-11-28" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/913704" patch="1">VU#913704</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2001:077-2">MDKSA-2001:077</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/8029">mandrake-apache-browse-directories(8029)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3"/>
        <vers num="1.3.1"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.6"/>
        <vers num="1.3.9"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
      </prod>
      <prod name="mandrake_single_network_firewall" vendor="mandrakesoft">
        <vers num="7.2"/>
      </prod>
      <prod name="mandrake_linux" vendor="mandrakesoft">
        <vers num="7.1"/>
        <vers num="7.3"/>
        <vers num="8.0"/>
      </prod>
      <prod name="mandrake_linux_corporate_server" vendor="mandrakesoft">
        <vers num="1.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1450" seq="2001-1450" published="2001-05-11" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/vuln-dev/2001/05/msg00029.html">20010505 [bug]: Cause IE 5.X to crash</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/199408">VU#199408</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10117">ie-ftp-url-dos(10117)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="5.0"/>
        <vers num="5.0.1" edition="sp1"/>
        <vers num="5.0.1" edition="sp2"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1451" seq="2001-1451" published="2002-10-22" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];296815">Q296815</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/887393">VU#887393</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6030" patch="1">6030</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10431">win2k-snmp-lanman-dos(10431)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1452" seq="2001-1452" published="2001-08-31" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name servers, which allows remote attackers to poison the DNS cache via spoofed DNS responses.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=KB;en-us;q241352" adv="1">Q241352</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/109475" adv="1">VU#109475</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6791" adv="1">6791</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/3675">nt-ms-dns-cachepollution(3675)</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
      <prod name="windows_nt" vendor="microsoft">
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1453" seq="2001-1453" published="2001-02-09" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Upgrade to the latest version of MySQL (3.23.33 or later) for fix.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev.mysql.com/doc/mysql/en/news-3-23-33.html">http://dev.mysql.com/doc/mysql/en/news-3-23-33.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/123384">VU#123384</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/161917">20010209 Some more MySql security issues</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6418">mysql-libmysqlclient-bo(6418)</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1454" seq="2001-1454" published="2001-02-09" modified="2019-10-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev.mysql.com/doc/mysql/en/news-3-23-33.html">http://dev.mysql.com/doc/mysql/en/news-3-23-33.html</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/367320" adv="1">VU#367320</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/161917">20010209 Some more MySql security issues</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6419">mysql-drop-database-bo(6419)</ref>
    </refs>
    <vuln_soft>
      <prod name="mysql" vendor="oracle">
        <vers num="3.23.32" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1455" seq="2001-1455" published="2001-08-24" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/837419" patch="1">VU#837419</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/6060">6060</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10497">siteminder-unicode-bypass(10497)</ref>
    </refs>
    <vuln_soft>
      <prod name="siteminder" vendor="netegrity">
        <vers num="3.6"/>
        <vers num="4.0"/>
        <vers num="4.5"/>
        <vers num="4.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1456" seq="2001-1456" published="2001-09-04" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011104-01-I" patch="1">20011104-01-I</ref>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-25.html">CA-2001-25</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/206723" patch="1">VU#206723</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3290">3290</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7088">gauntlet-csmap-bo(7088)</ref>
    </refs>
    <vuln_soft>
      <prod name="webshield_smtp" vendor="mcafee">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
      <prod name="gauntlet_firewall" vendor="network_associates">
        <vers num="4.2"/>
        <vers num="unix_5.0"/>
        <vers num="unix_5.5"/>
        <vers num="unix_6.0"/>
      </prod>
      <prod name="mcafee_e-ppliance" vendor="network_associates">
        <vers num="100_series"/>
        <vers num="120_series"/>
      </prod>
      <prod name="e-ppliance_300" vendor="pgp">
        <vers num="1.0"/>
        <vers num="1.5"/>
        <vers num="2.0"/>
      </prod>
      <prod name="irix" vendor="sgi">
        <vers num="6.2"/>
        <vers num="6.3"/>
        <vers num="6.4"/>
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1457" seq="2001-1457" published="2002-01-30" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/229955">VU#229955</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/173050">20010331 Remote buffer overflow in CrazyWWWBoard.</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10110">crazywwwboard-httpuseragent-bo(10110)</ref>
    </refs>
    <vuln_soft>
      <prod name="crazywwwboard" vendor="nobreak_technologies">
        <vers num="2000lep5"/>
        <vers num="2000p4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1458" seq="2001-1458" published="2001-10-15" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Novell GroupWise 5.5 and 6.0 allows remote attackers to read arbitrary files via a request for /servlet/webacc?User.html= that contains "../" (dot dot) sequences and a null character.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/220667">20011015 Novell Groupwise arbitrary file retrieval vulnerability</ref>
      <ref source="MISC" url="http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&amp;subcontent=/resources/advisories_template.htm%3Findexid%3D12">http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&amp;subcontent=/resources/advisories_template.htm%3Findexid%3D12</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/341539">VU#341539</ref>
      <ref source="CONFIRM" url="http://www.novell.com/coolsolutions/gwmag/features/a_webaccess_security_gw.html">http://www.novell.com/coolsolutions/gwmag/features/a_webaccess_security_gw.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3436">3436</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7287">novell-groupwise-directory-traversal(7287)</ref>
    </refs>
    <vuln_soft>
      <prod name="groupwise" vendor="novell">
        <vers num="5.5" edition=":enhancement_pack"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1459" seq="2001-1459" published="2001-06-19" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99324968918628&amp;w=2">20010619 pam session</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/797027" adv="1">VU#797027</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2917" adv="1">2917</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6757">openssh-rsh-bypass-pam(6757)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.5"/>
        <vers num="2.5.1"/>
        <vers num="2.5.2"/>
        <vers num="2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1460" seq="2001-1460" published="2001-10-13" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0088.html" patch="1">20011012 Bug in PostNuke 0.62, 0.63 and 0.64 (and possibly PHPnuke)</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0091.html">20011013 Bug in PostNuke 0.62, 0.63 and 0.64 (and possibly PHPnuke)</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/921547" adv="1">VU#921547</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3435" patch="1">3435</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7280">postnuke-getusrinfo-bypass-authentication(7280)</ref>
    </refs>
    <vuln_soft>
      <prod name="postnuke" vendor="postnuke_software_foundation">
        <vers num="0.62"/>
        <vers num="0.63"/>
        <vers num="0.64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1461" seq="2001-1461" published="2001-10-22" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/348040" adv="1">VU#348040</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3461" adv="1">3461</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7397">securid-webid-unicode-traversal(7397)</ref>
    </refs>
    <vuln_soft>
      <prod name="securid" vendor="rsa">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1462" seq="2001-1462" published="2001-10-24" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/609840" adv="1">VU#609840</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3462" adv="1">3462</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7399">securid-webid-debug-mode(7399)</ref>
    </refs>
    <vuln_soft>
      <prod name="securid" vendor="rsa">
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1463" seq="2001-1463" published="2001-11-19" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1002882">1002882</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/279763">VU#279763</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7925">servu-ftp-plaintext-password(7925)</ref>
    </refs>
    <vuln_soft>
      <prod name="serv-u" vendor="serv-u">
        <vers num="3.0.0.16"/>
        <vers num="3.0.0.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1464" seq="2001-1464" published="2001-01-10" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/403307" adv="1">VU#403307</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7928">crystalreports-plaintext-auth-info(7928)</ref>
    </refs>
    <vuln_soft>
      <prod name="crystal_reports" vendor="businessobjects">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1465" seq="2001-1465" published="2002-02-26" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1001801">1001801</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/139315">VU#139315</ref>
    </refs>
    <vuln_soft>
      <prod name="superscout_web_filter" vendor="surfcontrol">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1466" seq="2001-1466" published="2001-12-30" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q4/0967.html">20011230 blackshell1: Multiple Prolems with Vandykes SecureCRT</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/216227">VU#216227</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/10111">securecrt-ssh1-protocol-bo(10111)</ref>
    </refs>
    <vuln_soft>
      <prod name="securecrt" vendor="van_dyke_technologies">
        <vers num="3.4.1" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1467" seq="2001-1467" published="2001-04-11" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html">20010411 flaw in RH ``mkpasswd'' command</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html">20010412 Re: flaw in RH ``mkpasswd'' command (importance of seeds &amp; algorithms)</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1001303">1001303</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/527736">VU#527736</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2632">2632</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6382">mkpasswd-weak-passwords(6382)</ref>
    </refs>
    <vuln_soft>
      <prod name="expect" vendor="don_libes">
        <vers num="5.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1468" seq="2001-1468" published="2001-02-07" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1001408">1001408</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/391347">VU#391347</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2970">2970</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6774">phpsecurepages-checklogin-execute-code(6774)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpsecurepages" vendor="secure_reality">
        <vers num="0.11_beta"/>
        <vers num="0.12_beta"/>
        <vers num="0.13_beta"/>
        <vers num="0.14_beta"/>
        <vers num="0.15_beta"/>
        <vers num="0.16_beta"/>
        <vers num="0.17_beta"/>
        <vers num="0.18_beta"/>
        <vers num="0.19_beta"/>
        <vers num="0.20_beta"/>
        <vers num="0.21_beta"/>
        <vers num="0.22_beta"/>
        <vers num="0.23_beta"/>
        <vers num="0.24_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1469" seq="2001-1469" published="2001-01-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message's cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/25309">VU#25309</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6449">ssh-rc4-modify-packets(6449)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1470" seq="2001-1470" published="2001-01-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/315308">VU#315308</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6472">ssh-idea-modify-packets(6472)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1471" seq="2001-1471" published="2001-07-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-08/0123.html">20010810 Easily and Remotely Pipe a Covert Shell on phpBB version 1.4.0 and below</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-08/0087.html">20010804 Re: phpBB 1.4.0 bug leads to easy admin privileges</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/920931" adv="1">VU#920931</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3167" patch="1">3167</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6944">phpbb-admin-access(6944)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="1.0.0"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.4.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1472" seq="2001-1472" published="2001-08-03" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/314347">VU#314347</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201715">20010803 phpBB 1.4.0 bug leads to easy admin privileges</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3142">3142</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6944">phpbb-admin-access(6944)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1473" seq="2001-1473" published="2001-01-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/684820">VU#684820</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6603">ssh-authentication-forwarding(6603)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1474" seq="2001-1474" published="2001-01-18" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">SSH before 2.0 disables host key checking when connecting to the localhost, which allows remote attackers to silently redirect connections to the localhost by poisoning the client's DNS cache.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/786900" adv="1">VU#786900</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6604">ssh-dns-authentication-bypass(6604)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1475" seq="2001-1475" published="2001-01-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/665372" patch="1">VU#665372</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6490">ssh-rc4-replay-conversation(6490)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1476" seq="2001-1476" published="2001-01-18" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/565052" patch="1">VU#565052</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6490">ssh-rc4-replay-conversation(6490)</ref>
    </refs>
    <vuln_soft>
      <prod name="ssh" vendor="ssh">
        <vers num="1.2.24"/>
        <vers num="1.2.25"/>
        <vers num="1.2.26"/>
        <vers num="1.2.27"/>
        <vers num="1.2.28"/>
        <vers num="1.2.29"/>
        <vers num="1.2.30"/>
        <vers num="1.2.31"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1477" seq="2001-1477" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The Domain gateway in BEA Tuxedo 7.1 does not perform authorization checks for imported services and qspaces on remote domains, even when an ACL exists, which allows users to access services in a remote domain.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA00-08.jsp" patch="1">http://dev2dev.bea.com/resourcelibrary/advisoriesnotifications/BEA00-08.jsp</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6326">bea-tuxedo-remote-access(6326)</ref>
    </refs>
    <vuln_soft>
      <prod name="tuxedo" vendor="bea">
        <vers num="7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1478" seq="2001-1478" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in xlock in UnixWare 7.1.0 and 7.1.1 and Open Unix 8.0.0 allows local users to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.34/CSSA-2001-SCO.34.txt" patch="1">CSSA-2001-SCO.34</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3555" patch="1">3555</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7573">unixware-openunix-xlock-bo(7573)</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="caldera">
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
      <prod name="openunix" vendor="caldera">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1479" seq="2001-1479" published="2001-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/6K00S203FC.html" adv="1">http://www.securiteam.com/unixfocus/6K00S203FC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3763" patch="1">3763</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7756">sun-smcboot-tmp-symlink(7756)</ref>
    </refs>
    <vuln_soft>
      <prod name="management+center" vendor="sun">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1480" seq="2001-1480" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/10/msg00120.html">20011017 Mac OS X v10.0.x J2SE v1.3 clipboard tapping vulnerability</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3617" adv="1" patch="1">HPSBUX0110-174</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3441" patch="1">3441</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7333">jre-system-clipboard-access(7333)</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_runtime_for_java" vendor="apple">
        <vers num="2.2.4" edition=":java"/>
      </prod>
      <prod name="jdk" vendor="sun">
        <vers num="1.2.2_07" edition=":linux"/>
        <vers num="1.2.2_07" edition=":solaris"/>
        <vers num="1.2.2_07" edition=":windows"/>
        <vers num="1.2.2_07a" edition=":solaris"/>
        <vers num="1.3.0_02" edition=":linux"/>
        <vers num="1.3.0_02" edition=":solaris"/>
        <vers num="1.3.0_02" edition=":windows"/>
      </prod>
      <prod name="jre" vendor="sun">
        <vers num="1.2.2" edition=":linux_production"/>
        <vers num="1.2.2_003" edition=":linux_production"/>
        <vers num="1.2.2_004" edition=":linux"/>
        <vers num="1.2.2_005" edition=":linux"/>
        <vers num="1.2.2_006" edition=":linux"/>
        <vers num="1.2.2_007" edition=":linux"/>
        <vers num="1.2.2_007" edition=":solaris"/>
        <vers num="1.2.2_007" edition=":windows"/>
        <vers num="1.3.0" edition=":linux"/>
        <vers num="1.3.0" edition="update1:linux"/>
        <vers num="1.3.0" edition="update2:linux"/>
        <vers num="1.3.0" edition="update2:solaris"/>
        <vers num="1.3.0" edition="update2:windows"/>
      </prod>
      <prod name="sdk" vendor="sun">
        <vers num="1.1.3"/>
        <vers num="1.3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1481" seq="2001-1481" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html" adv="1">http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/242375">20011126 Xitami Webserver stores admin password in clear text.</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3582">3582</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7600">xitami-default-password-plaintext(7600)</ref>
    </refs>
    <vuln_soft>
      <prod name="xitami" vendor="imatix">
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5_b4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1482" seq="2001-1482" published="2001-12-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL queries via the $sortby variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3411">3411</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7253">phpbb-bbmemberlist-modify-sql(7253)</ref>
    </refs>
    <vuln_soft>
      <prod name="phpbb" vendor="phpbb_group">
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1483" seq="2001-1483" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3549">3549</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7572">opie-verify-accounts(7572)</ref>
    </refs>
    <vuln_soft>
      <prod name="opie" vendor="nrl">
        <vers num="2.4"/>
        <vers num="2.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1484" seq="2001-1484" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and configuration via a bounce attack from a system on the local area network (LAN) side, which is allowed to access TFTP without authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CERT" url="http://www.cert.org/advisories/CA-2001-08.html" adv="1">CA-2001-08</ref>
      <ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/211736" adv="1">VU#211736</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6336">alcatel-tftp-lan-access(6336)</ref>
    </refs>
    <vuln_soft>
      <prod name="adsl_modem_1000" vendor="alcatel">
        <vers num=""/>
      </prod>
      <prod name="speed_touch_adsl_modem" vendor="alcatel">
        <vers num="home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1487" seq="2001-1487" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7707">qpopper-popauth-symlink(7707)</ref>
    </refs>
    <vuln_soft>
      <prod name="qpopper" vendor="qualcomm">
        <vers num="4.0" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1488" seq="2001-1488" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet.  NOTE: a followup post suggests that this is not an issue in the daemon.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7283">irc-openprojects-dns-spoofing(7283)</ref>
    </refs>
    <vuln_soft>
      <prod name="open_projects_network_ircd" vendor="open_projects_network">
        <vers num="u2.10.05.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1489" seq="2001-1489" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3684">3684</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7709">win-browser-image-dos(7709)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1490" seq="2001-1490" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3684">3684</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7709">win-browser-image-dos(7709)</ref>
    </refs>
    <vuln_soft>
      <prod name="mozilla" vendor="mozilla">
        <vers num="0.9.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1491" seq="2001-1491" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BID" url="http://www.securityfocus.com/bid/3684">3684</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7709">win-browser-image-dos(7709)</ref>
    </refs>
    <vuln_soft>
      <prod name="opera_web_browser" vendor="opera_software">
        <vers num="5.1.1" edition=":win32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1492" seq="2001-1492" published="2001-12-31" modified="2008-09-10" reject="1">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2001-1460.  Reason: This candidate is a refinement duplicate of CVE-2001-1460.  Notes: All CVE users should reference CVE-2001-1460 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" name="CVE-2001-1494" seq="2001-1494" published="2001-12-31" modified="2017-10-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Dec/0122.html">20011213 Silly 'script' hardlink bug - fixed</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Dec/0123.html">20011212 Silly 'script' hardlink bug</ref>
      <ref source="MISC" url="http://support.avaya.com/elmodocs2/security/ASA-2006-014.htm">http://support.avaya.com/elmodocs2/security/ASA-2006-014.htm</ref>
      <ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-782.html" adv="1">RHSA-2005:782</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/16280">16280</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7718">util-linux-script-hardlink(7718)</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10723">oval:org.mitre.oval:def:10723</ref>
    </refs>
    <vuln_soft>
      <prod name="util-linux" vendor="andries_brouwer">
        <vers num="2.11m" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1495" seq="2001-1495" published="2001-12-31" modified="2017-07-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the target parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-10/0179.html">20011022 [Advisory iSecureLabs] Network Query Tool remote command execution</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3455">3455</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7322">nqt-php-command-execution(7322)</ref>
    </refs>
    <vuln_soft>
      <prod name="network_query_tool" vendor="freshmeat">
        <vers num="1.0"/>
      </prod>
      <prod name="network_query_tool_phpnuke" vendor="freshmeat">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1496" seq="2001-1496" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/241310">20011120 Off-by-one vulnerability in thttpd!!!</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/241953">20011123 Re: Off-by-one vulnerability in thttpd!!!</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3562">3562</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7595">thttpd-basic-authentication-bo(7595)</ref>
    </refs>
    <vuln_soft>
      <prod name="thttpd" vendor="acme_labs">
        <vers num="1.95"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="2.13"/>
        <vers num="2.14"/>
        <vers num="2.15"/>
        <vers num="2.16"/>
        <vers num="2.17"/>
        <vers num="2.18"/>
        <vers num="2.19"/>
        <vers num="2.20"/>
        <vers num="2.20b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1497" seq="2001-1497" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7592.php">ie-password-character-information(7592)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/241323">20011121 MS IE Password inputs</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/241400">20011120 Re: MS IE Password inputs</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3563">3563</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="4.0" edition=":windows_nt"/>
        <vers num="4.0.1" edition=":windows_98"/>
        <vers num="4.0.1" edition=":windows_nt"/>
        <vers num="4.0.1" edition="sp2"/>
        <vers num="4.1" edition=":windows_95"/>
        <vers num="4.1" edition=":windows_98"/>
        <vers num="4.1" edition=":windows_nt_4.0"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1498" seq="2001-1498" published="2001-12-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in mod_bf 0.2 allows local users to execute arbitrary commands via a long script.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.bugtraq.org/advisories/GOBBLES-15.txt">http://www.bugtraq.org/advisories/GOBBLES-15.txt</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3713">3713</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7730">brainf*ck-modbf-bo(7730)</ref>
    </refs>
    <vuln_soft>
      <prod name="mod_bf" vendor="markus_kliegl">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1499" seq="2001-1499" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/222366">20011023 Check Point VPN-1 SecuRemote Flaw</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/222479">20011024 RE: Check Point VPN-1 SecuRemote Flaw</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3470">3470</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7343">vpn1-securemote-brute-force(7343)</ref>
    </refs>
    <vuln_soft>
      <prod name="vpn-1" vendor="checkpoint">
        <vers num="4.1" edition="sp4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1500" seq="2001-1500" published="2001-12-31" modified="2017-12-18" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward resolution, which allows remote attackers to bypass ACLs or cause an incorrect client hostname to be logged.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000450">CLA-2002:450</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2002:005">MDKSA-2002:005</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/212805">20010907 ProFTPd and reverse DNS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3310" patch="1">3310</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7126">proftpd-unresolved-hostname(7126)</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2"/>
        <vers num="1.2.0_rc3"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.2_rc1"/>
        <vers num="1.2.2_rc2"/>
        <vers num="1.2_pre1"/>
        <vers num="1.2_pre2"/>
        <vers num="1.2_pre3"/>
        <vers num="1.2_pre4"/>
        <vers num="1.2_pre5"/>
        <vers num="1.2_pre6"/>
        <vers num="1.2_pre7"/>
        <vers num="1.2_pre8"/>
        <vers num="1.2_pre9"/>
        <vers num="1.2_pre10"/>
        <vers num="1.2_pre11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1501" seq="2001-1501" published="2001-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The glob functionality in ProFTPD 1.2.1, and possibly other versions allows remote attackers to cause a denial of service (CPU and memory consumption) via commands with large numbers of wildcard and other special characters, as demonstrated using an ls command with multiple (1) "*/..", (2) "*/.*", or (3) ".*./*?/" sequences in the argument.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000450">CLA-2002:450</ref>
      <ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2002:005">MDKSA-2002:005</ref>
    </refs>
    <vuln_soft>
      <prod name="proftpd" vendor="proftpd_project">
        <vers num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1502" seq="2001-1502" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the NEXTPAGE parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/221688">20011019 Webcart v.8.4</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3453">3453</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7315">webcart-cgi-command-execution(7315)</ref>
    </refs>
    <vuln_soft>
      <prod name="webcart" vendor="mountain_network_systems">
        <vers num="8.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1503" seq="2001-1503" published="2001-12-31" modified="2018-10-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0016.html">20011022 Solaris fingerd disclose complete user list</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-27116-1" adv="1">27116</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3457">3457</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7334">solaris-fingerd-list-accounts(7334)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.5" edition=":x86"/>
        <vers num="5.5.1" edition=":x86"/>
        <vers num="5.6" edition=":x86"/>
        <vers num="5.7" edition=":x86"/>
        <vers num="5.8" edition=":x86"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1504" seq="2001-1504" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/221986">20011022 Security BugWare Advisory</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/222212">20011023 Re: Security BugWare Advisory</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3458">3458</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7323">lotus-notes-execute-objects(7323)</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_notes" vendor="ibm">
        <vers num="4.6"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1505" seq="2001-1505" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/249142">20020109 Security flaws in tinc</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3837">3837</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7870">vpn-replay-attack(7870)</ref>
    </refs>
    <vuln_soft>
      <prod name="tinc" vendor="tinc">
        <vers num="1.0pre3"/>
        <vers num="1.0pre4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1506" seq="2001-1506" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional user privileges on some files beyond what is specified in the file system protection rules, which allows local users to conduct unauthorized operations on restricted files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://online.securityfocus.com/advisories/3618">HPSBTL0110-001</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3468">3468</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7342">hp-secure-unauth-privileges(7342)</ref>
    </refs>
    <vuln_soft>
      <prod name="secure_os" vendor="hp">
        <vers num="1.0" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1507" seq="2001-1507" published="2001-12-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://msgs.securepoint.com/cgi-bin/get/bugtraq0111/114.html" adv="1" patch="1">20011119 OpenSSH 3.0.1 (fwd)</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7598.php" patch="1">openssh-kerberos-elevate-privileges(7598)</ref>
      <ref source="CONFIRM" url="http://www.openbsd.org/errata30.html#sshd" patch="1">http://www.openbsd.org/errata30.html#sshd</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3560">3560</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="3.0"/>
        <vers num="3.0p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1508" seq="2001-1508" published="2001-12-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.38/CSSA-2001-SCO.38.txt" patch="1">CSSA-2001-SCO.38</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2597" patch="1">2597</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6413">sco-openserver-lpstat-bo(6413)</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1509" seq="2001-1509" published="2001-12-31" modified="2017-10-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7324.php">hpux-ia-geteuid-gain-privileges(7324)</ref>
      <ref source="HP" url="http://www.securityfocus.com/advisories/3606" patch="1">HPSBUX0110-171</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3452" patch="1">3452</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5364">oval:org.mitre.oval:def:5364</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="11.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1510" seq="2001-1510" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other web servers allows remote attackers to read arbitrary files and directories by appending (1) "%3f.jsp", (2) "?.jsp" or (3) "?" to the requested URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7623.php">allaire-jrun-view-directory(7623)</ref>
      <ref source="ALLAIRE" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=22262&amp;Method=Full" adv="1">MPSB01-13</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3592">3592</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.3"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1511" seq="2001-1511" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JSP) source code via a request URL containing the source filename ending in (1) "jsp%00" or (2) "js%2570".</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7676.php" patch="1">allaire-jrun-view-jsp-source(7676)</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=22288&amp;Method=Full" adv="1" patch="1">http://www.macromedia.com/v1/handlers/index.cfm?ID=22288&amp;Method=Full</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1512" seq="2001-1512" published="2001-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directories and execute arbitrary JavaServer Pages (JSP), a variant of CVE-2000-1050.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7677.php" patch="1">allaire-jrun-webinf-metainf-jsp(7677)</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=22287" adv="1" patch="1">http://www.macromedia.com/v1/handlers/index.cfm?ID=22287</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3662">3662</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1513" seq="2001-1513" published="2001-12-31" modified="2008-09-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trailing '/' (slash), as demonstrated using ctx.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7680.php" patch="1">allaire-jrun-sessionid-duplicated(7680)</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=22260&amp;Method=Full" adv="1" patch="1">http://www.macromedia.com/v1/handlers/index.cfm?ID=22260&amp;Method=Full</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3600">3600</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1514" seq="2001-1514" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with &lt;CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with &lt;CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://www.macromedia.com/v1/Handlers/index.cfm?ID=22263" adv="1">http://www.macromedia.com/v1/Handlers/index.cfm?ID=22263</ref>
    </refs>
    <vuln_soft>
      <prod name="coldfusion" vendor="macromedia">
        <vers num="4.5"/>
        <vers num="5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1515" seq="2001-1515" published="2001-12-31" modified="2019-04-30" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1002626" adv="1">1002626</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3479">3479</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1516" seq="2001-1516" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7218.php" patch="1">phpreview-cross-site-scripting(7218)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3380" patch="1">3380</ref>
    </refs>
    <vuln_soft>
      <prod name="phpreview" vendor="hans_wolters">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.9_final"/>
        <vers num="0.9_rc1"/>
        <vers num="0.9_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1517" seq="2001-1517" published="2001-12-31" modified="2019-04-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">** DISPUTED ** RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command.  NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0041.html" adv="1" patch="1">20011112 RADIX1112200102</ref>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00100.html">20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7531.php" patch="1">win2k-runas-reveal-information(7531)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3184">3184</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1518" seq="2001-1518" published="2001-12-31" modified="2019-04-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service.  NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00100.html">20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7533.php">win2k-runas-dos(7533)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3291">3291</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1519" seq="2001-1519" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="3.6" CVSS_base_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">** DISPUTED ** RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service.  NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/236111">20011112 RADIX1112200101</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/240136">20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7532.php">win2k-runas-pipe-authentication(7532)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3185">3185</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1520" seq="2001-1520" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-11/0187.html">20011123 Xircom REX6000 PDA Password Retrieval</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7584.php">rex6000-pda-password-retrieval(7584)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3574">3574</ref>
    </refs>
    <vuln_soft>
      <prod name="xircom_rex_6000" vendor="intel">
        <vers num="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1521" seq="2001-1521" published="2001-12-31" modified="2008-09-10" severity="Low" CVSS_version="2.0" CVSS_score="2.6" CVSS_base_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/245691">20011215 PHPNuke holes</ref>
      <ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/82/243545">20011203 Phpnuke Cross site scripting vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7654.php">phpnuke-postnuke-css(7654)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3609">3609</ref>
    </refs>
    <vuln_soft>
      <prod name="postnuke" vendor="postnuke_software_foundation">
        <vers num="0.62"/>
        <vers num="0.63"/>
        <vers num="0.64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1522" seq="2001-1522" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in im.php in IMessenger for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via a message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q4/0848.html">20011215 Security hole in IMessenger ( PHP-Nuke )</ref>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q4/0851.html">20011215 Serious bug in IMessenger ( php-nuke )</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="8.0_final"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1523" seq="2001-1523" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the DMOZGateway module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the topic parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q4/0853.html">20011216 CSS in DMOZGateway ( php-nuke )</ref>
    </refs>
    <vuln_soft>
      <prod name="dmozgateway" vendor="dmozgateway">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1524" seq="2001-1524" published="2001-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CONFIRM" url="http://prdownloads.sourceforge.net/phpnuke/PHP-Nuke-5.5.tar.gz" patch="1">http://prdownloads.sourceforge.net/phpnuke/PHP-Nuke-5.5.tar.gz</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7654.php">phpnuke-postnuke-css(7654)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3609">3609</ref>
    </refs>
    <vuln_soft>
      <prod name="php-nuke" vendor="francisco_burzi">
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="4.3"/>
        <vers num="4.4"/>
        <vers num="4.4.1a"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.2a"/>
        <vers num="5.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1525" seq="2001-1525" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html">20011201 easynews 1.5 let's remote users modify database</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7657.php">easynews-php-modify-data(7657)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3643">3643</ref>
    </refs>
    <vuln_soft>
      <prod name="easynews" vendor="easyscripts">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1526" seq="2001-1526" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.3" CVSS_base_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html">20011201 easynews 1.5 let's remote users modify database</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7658.php">easynews-php-css(7658)</ref>
    </refs>
    <vuln_soft>
      <prod name="easynews" vendor="easyscripts">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1527" seq="2001-1527" published="2001-12-31" modified="2009-04-03" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0000.html">20011201 easynews 1.5 let's remote users modify database</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7659.php">easynews-php-admin-passwd(7659)</ref>
    </refs>
    <vuln_soft>
      <prod name="easynews" vendor="easyscripts">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1528" seq="2001-1528" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html" adv="1">20010929 Vulnerability in Amtote International  homebet self service wagering system.</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7185.php">homebet-brute-force-account(7185)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3371">3371</ref>
    </refs>
    <vuln_soft>
      <prod name="homebet" vendor="amtote_international">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1529" seq="2001-1529" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string.  NOTE: due to lack of details in the vendor advisory, it is not clear if this is the same issue as CVE-2001-0779.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/aix/2001-q4/0009.html" adv="1">IY21609</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1530" seq="2001-1530" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0015.html" adv="1">20011022 Webmin 0.88 temporary insecure file creation, root compromise</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/6R00M0K2UC.html" adv="1">http://www.securiteam.com/unixfocus/6R00M0K2UC.html</ref>
    </refs>
    <vuln_soft>
      <prod name="webmin" vendor="webmin">
        <vers num="0.80"/>
        <vers num="0.88"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1531" seq="2001-1531" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0162.html">20011019 Claris Emailer buffer over flow vulnerabirity</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7314.php">claris-long-filename-bo(7314)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3454">3454</ref>
    </refs>
    <vuln_soft>
      <prod name="claris_emailer" vendor="apple">
        <vers num="2.0v2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1532" seq="2001-1532" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7458.php">webcrossing-webx-session-hijack(7458)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/223799">20011030 Web Forum Account Hijacking Vuln.</ref>
    </refs>
    <vuln_soft>
      <prod name="webx" vendor="web_crossing">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1533" seq="2001-1533" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets.  NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability.  Therefore this "laws of physics" issue might not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00018.html">20011102 Microsoft ISA Server Fragmented Udp Flood Vulnerability</ref>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00031.html">20051101 RE: Microsoft ISA Server Fragmented Udp Flood Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7446.php">isa-udp-flood-dos(7446)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3501">3501</ref>
    </refs>
    <vuln_soft>
      <prod name="isa_server" vendor="microsoft">
        <vers num="2000"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1534" seq="2001-1534" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html">20011113 Brute-Forcing Web Application Session IDs</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7494.php">apache-modusertrack-predicticable-sessionid(7494)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3521">3521</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.14"/>
        <vers num="1.3.17"/>
        <vers num="1.3.18"/>
        <vers num="1.3.19"/>
        <vers num="1.3.20" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1535" seq="2001-1535" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00084.html">20011113 Brute-Forcing Web Application Session IDs</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7493.php">slashcode-sessionid-brute-force(7493)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3519">3519</ref>
    </refs>
    <vuln_soft>
      <prod name="slashcode" vendor="open_source_development_network">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1536" seq="2001-1536" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-11/0225.html">20011127 Audiogalaxy again</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7621.php">audiogalaxy-plaintext-password(7621)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3587">3587</ref>
    </refs>
    <vuln_soft>
      <prod name="autogalaxy" vendor="autogalaxy">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1537" seq="2001-1537" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-11/0245.html">20011128 TWIG default configurations may lead to insecure auth-cookie password storage</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7619.php">twig-password-plaintext-cookie(7619)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3591">3591</ref>
    </refs>
    <vuln_soft>
      <prod name="webmail" vendor="twig">
        <vers num="2.7.4" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1538" seq="2001-1538" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SpeedXess HA-120 DSL router has a default administrative password of "speedxess", which allows remote attackers to gain access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0032.html" patch="1">20011203 SpeedXess HASE-120 router default password</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7655.php">speedxess-hase-default-password(7655)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3617">3617</ref>
    </refs>
    <vuln_soft>
      <prod name="ha-120_dsl_router" vendor="speedxess">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1539" seq="2001-1539" published="2001-12-31" modified="2010-01-08" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function.  NOTE: the vendor could not reproduce the problem.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0008.html" adv="1">20011202 Stack overflow in all Internet Explorer Versions!!</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0034.html">20011204 RE: Stack overflow in all Internet Explorer Versions!!</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7661.php">ie-settimeout-dos(7661)</ref>
    </refs>
    <vuln_soft>
      <prod name="ie" vendor="microsoft">
        <vers num="6.0.2900"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1540" seq="2001-1540" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0047.html">20011205 IPRoute Fragmentation Denial of Service Vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7664.php">iproute-fragmented-packet-dos(7664)</ref>
    </refs>
    <vuln_soft>
      <prod name="iproute" vendor="david_f._mischler">
        <vers num="0.973"/>
        <vers num="0.974"/>
        <vers num="1.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1541" seq="2001-1541" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Unix-to-Unix Copy Protocol (UUCP) in BSDI BSD/OS 3.0 through 4.2 allows local users to execute arbitrary code via a long command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7633.php">bsd-uucp-bo(7633)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/243096">20011129 UUCP</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3603">3603</ref>
    </refs>
    <vuln_soft>
      <prod name="bsd_os" vendor="bsdi">
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1542" seq="2001-1542" published="2001-12-31" modified="2011-03-07" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-11/0294.html">20011130 Re: NAI Webshield SMTP for WinNT MIME header vuln that allows BadTrans to pass]</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7637.php">webshield-smtp-mime-attachments(7637)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3601">3601</ref>
    </refs>
    <vuln_soft>
      <prod name="webshield_smtp" vendor="network_associates">
        <vers num="4.5"/>
        <vers num="4.5_mr1a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1543" seq="2001-1543" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remote attackers to gain access to the camera.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0050.html">20011205 Axis Network Camera known default password vulnerability</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0061.html">20011206 Re: Axis Network Camera known default password vulnerability</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7665.php">axis-default-admin-passwd(7665)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3640">3640</ref>
    </refs>
    <vuln_soft>
      <prod name="2100_network_camera" vendor="axis">
        <vers num=""/>
      </prod>
      <prod name="2110_network_camera" vendor="axis">
        <vers num=""/>
      </prod>
      <prod name="2120_network_camera" vendor="axis">
        <vers num=""/>
      </prod>
      <prod name="neteye_200" vendor="axis">
        <vers num=""/>
      </prod>
      <prod name="neteye_200+" vendor="axis">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1544" seq="2001-1544" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7678.php">allaire-jrun-jws-directory-traversal(7678)</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=22290&amp;Method=Full" adv="1" patch="1">http://www.macromedia.com/v1/handlers/index.cfm?ID=22290&amp;Method=Full</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3666" patch="1">3666</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="2.3.3"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1545" seq="2001-1545" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7679.php">allaire-jrun-jsessionid-appended(7679)</ref>
      <ref source="CONFIRM" url="http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&amp;Method=Full" adv="1" patch="1">http://www.macromedia.com/v1/handlers/index.cfm?ID=22291&amp;Method=Full</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3665" patch="1">3665</ref>
    </refs>
    <vuln_soft>
      <prod name="jrun" vendor="macromedia">
        <vers num="3.0"/>
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1546" seq="2001-1546" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7682.php">pathways-homecare-weak-encryption(7682)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3653">3653</ref>
    </refs>
    <vuln_soft>
      <prod name="pathways_homecare" vendor="mckesson">
        <vers num="6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1547" seq="2001-1547" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7670.php">oe-blocked-attachment-forward(7670)</ref>
    </refs>
    <vuln_soft>
      <prod name="outlook_express" vendor="microsoft">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1548" seq="2001-1548" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0056.html" adv="1">20011205 Flawed outbound packet filtering in various personal firewalls</ref>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0065.html">20011206 Re: Flawed outbound packet filtering in various personal firewalls</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7671.php">zonealarm-tiny-bypass-filter(7671)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3647">3647</ref>
    </refs>
    <vuln_soft>
      <prod name="zonealarm" vendor="zonelabs">
        <vers num="2.1"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4" edition=":pro"/>
        <vers num="2.5"/>
        <vers num="2.6" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1549" seq="2001-1549" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0056.html" adv="1">20011205 Flawed outbound packet filtering in various personal firewalls</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7671.php">zonealarm-tiny-bypass-filter(7671)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3647">3647</ref>
    </refs>
    <vuln_soft>
      <prod name="tiny_personal_firewall" vendor="tiny_software">
        <vers num="1.0"/>
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1550" seq="2001-1550" published="2001-12-31" modified="2017-07-10" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2001-q4/0205.html" adv="1" patch="1">20011226 Dangerous information in CentraOne log files - VENDOR RESPONSE</ref>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0072.html" adv="1">20011217 Dangerous information in CentraOne Log files, possible user impersonation</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3704">3704</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7820">centraone-log-file-info(7820)</ref>
    </refs>
    <vuln_soft>
      <prod name="asp" vendor="centra">
        <vers num=""/>
      </prod>
      <prod name="centraone" vendor="centra">
        <vers num="5.2"/>
      </prod>
      <prod name="smart_connect" vendor="centra">
        <vers num="cen5.2-03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1551" seq="2001-1551" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0179.html" adv="1">20011022 Overriding qouta limits in Linux kernel</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.2.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1552" seq="2001-1552" published="2001-12-31" modified="2008-09-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple Service Discovery Protocol (SSDP) message.  NOTE: multiple replies to the original post state that the problem could not be reproduced.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0133.html">20011017 Ssdpsrv.exe in WindowsME</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7318.php">winme-ssdp-dos(7318)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3442">3442</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_me" vendor="microsoft">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1553" seq="2001-1553" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in setiathome for SETI@home 3.03, if installed setuid, could allow local users to execute arbitrary code via long command line options (1) socks_server, (2) socks_user, and (3) socks_passwd. NOTE: since the default configuration of setiathome is not setuid, perhaps this issue should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q4/0662.html" adv="1">20011202 Vulnerability in SETI@home</ref>
    </refs>
    <vuln_soft>
      <prod name="seti_at_home" vendor="university_of_california">
        <vers num="3.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1554" seq="2001-1554" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via Path Maximum Transmit Unit (PMTU) IP packets.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/aix/2001-q4/0009.html">IY25096</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="430"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1555" seq="2001-1555" published="2001-12-31" modified="2018-10-30" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows local users to write to other users' terminals by modifying the ACL of a TTY.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1002732" adv="1">1002732</ref>
      <ref source="SECTRACK" url="http://securitytracker.com/id?1004035" adv="1" patch="1">1004035</ref>
      <ref source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-43929-1" adv="1" patch="1">43929</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3522" patch="1">3522</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition=":x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1556" seq="2001-1556" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0231.html" adv="1">20011024 Hidden requests to Apache</ref>
      <ref source="CONFIRM" url="http://httpd.apache.org/docs/logs.html">http://httpd.apache.org/docs/logs.html</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7363.php">apache-hidden-http-request(7363)</ref>
    </refs>
    <vuln_soft>
      <prod name="http_server" vendor="apache">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1557" seq="2001-1557" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY20486&amp;apar=only">IY20486</ref>
      <ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY23674&amp;apar=only">IY23674</ref>
    </refs>
    <vuln_soft>
      <prod name="aix" vendor="ibm">
        <vers num="4.3"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1558" seq="2001-1558" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (crash).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MLIST" url="http://archives.neohapsis.com/archives/snort/2001-11/0990.html" patch="1">[Snort-announce] 20011129 Snort 1.8.3 Released</ref>
    </refs>
    <vuln_soft>
      <prod name="snort" vendor="snort">
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1559" seq="2001-1559" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0014.html">20011202 OpenBSD local DoS</ref>
      <ref source="MLIST" url="http://monkey.org/openbsd/archive/tech/0112/msg00015.html">[OpenBSD] 20011202 Code that crashes kernel at will + proposed patch</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7690.php">openbsd-retval-null-dos(7690)</ref>
    </refs>
    <vuln_soft>
      <prod name="openbsd" vendor="openbsd">
        <vers num="2.9"/>
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1560" seq="2001-1560" published="2001-12-31" modified="2019-04-30" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Win32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service (system crash) by calling the ShowWindow function after receiving a WM_NCCREATE message.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="NTBUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/NT-Bugtraq/2001-10/0066.html">20011027 A GDI bug.</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7409.php">win-gid-dos(7409)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3481">3481</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_2000" vendor="microsoft">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp2"/>
      </prod>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1561" seq="2001-1561" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0024.html">20010702 Xvt 2.1 vulnerability</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-082" adv="1" patch="1">DSA-082</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6781.php">xvt-command-line-bo(6781)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2955">2955</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2964" patch="1">2964</ref>
    </refs>
    <vuln_soft>
      <prod name="xvt" vendor="john_bovey">
        <vers num="2.1"/>
      </prod>
      <prod name="debian_linux" vendor="debian">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1562" seq="2001-1562" published="2001-12-31" modified="2016-10-17" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Format string vulnerability in nvi before 1.79 allows local users to gain privileges via format string specifiers in a filename.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="SUSE" url="http://marc.info/?l=bugtraq&amp;m=100526142205694&amp;w=2">SuSE-SA:2001:040</ref>
      <ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-085" adv="1" patch="1">DSA-085</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7317.php">nvi-format-string(7317)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3456">3456</ref>
    </refs>
    <vuln_soft>
      <prod name="nvi" vendor="bsd">
        <vers num="1.79"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1563" seq="2001-1563" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q4/0062.html" patch="1">HPSBTL0112-004</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/42892">tomcat-unspecified-unauthorized-access(42892)</ref>
    </refs>
    <vuln_soft>
      <prod name="tomcat" vendor="apache">
        <vers num="3.2.1"/>
      </prod>
      <prod name="secure_os" vendor="hp">
        <vers num="1.0" edition=":linux"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1564" seq="2001-1564" published="2001-12-31" modified="2017-10-11" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropped, which could allow local users to cause a denial of service by exhausting available disk space.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q3/0000.html">HPSBUX0107-156</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6810.php">hpux-setrlimit-dos(6810)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3416">3416</ref>
      <ref source="OVAL" url="https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5159">oval:org.mitre.oval:def:5159</ref>
    </refs>
    <vuln_soft>
      <prod name="hp-ux" vendor="hp">
        <vers num="10.01"/>
        <vers num="10.10"/>
        <vers num="10.20"/>
        <vers num="10.24"/>
        <vers num="11.00"/>
        <vers num="11.04"/>
        <vers num="11.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1565" seq="2001-1565" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/7750.php">macos-ppp-auth-disclosure(7750)</ref>
      <ref source="MLIST" url="http://www.macsecurity.org/pipermail/macsec/2001-December/000299.html">[Macsec] 20011229 MacOSX ppp</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3753">3753</ref>
    </refs>
    <vuln_soft>
      <prod name="mac_os_x" vendor="apple">
        <vers num="10.0"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1566" seq="2001-1566" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Format string vulnerability in libvanessa_logger 0.0.1 in Perdition 0.1.8 allows remote attackers to execute arbitrary code via format string specifiers in the __vanessa_logger_log function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="VULNWATCH" url="http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0082.html" adv="1">20011225 GOBBLES #17: perdition/vanessa_logger format string vuln</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-12/0260.html" adv="1">20011225 Remote Root Hole in FreeBSD Ports</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3740" patch="1">3740</ref>
    </refs>
    <vuln_soft>
      <prod name="vanessa_logger" vendor="vanessa">
        <vers num="0.0.1"/>
      </prod>
      <prod name="perdition" vendor="verge">
        <vers num="0.1.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1567" seq="2001-1567" published="2001-12-31" modified="2016-10-17" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101284222932568&amp;w=2">20020203 Lotus Domino password bypass</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101285903120879&amp;w=2">20020204 Re: Lotus Domino password bypass</ref>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=101286525008089&amp;w=2">20020204 Lotus Domino password bypass</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/8072.php">lotus-domino-auth-bypass(8072)</ref>
      <ref source="MISC" url="http://www.nextgenss.com/papers/hpldws.pdf" adv="1">http://www.nextgenss.com/papers/hpldws.pdf</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/4022">4022</ref>
    </refs>
    <vuln_soft>
      <prod name="lotus_domino" vendor="ibm">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4" edition=":solaris"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7" edition=":solaris"/>
        <vers num="5.0.7a"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
      </prod>
      <prod name="lotus_domino_server" vendor="ibm">
        <vers num="5.0.9a" prev="1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1568" seq="2001-1568" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-07/0127.html">20010709 Many WAP gateways do not properly check SSL certificates</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/6814.php">wap-gateway-ssl-certificates(6814)</ref>
    </refs>
    <vuln_soft>
      <prod name="wap_gateway" vendor="cmg">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1569" seq="2001-1569" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="6.4" CVSS_base_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)">
    <desc>
      <descript source="cve">Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate authorities, which allows remote attackers to spoof SSL certificates via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="XF" url="http://www.iss.net/security_center/static/6814.php">wap-gateway-ssl-certificates(6814)</ref>
      <ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/195619">20010709 Many WAP gateways do not properly check SSL certificates</ref>
    </refs>
    <vuln_soft>
      <prod name="openwave_wap_gateway" vendor="cmg">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1570" seq="2001-1570" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Windows XP with fast user switching and account lockout enabled allows local users to deny user account access by setting the fast user switch to the same user (self) multiple times, which causes other accounts to be locked out.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0213.html">20011220 Windows XP security concerns</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7731.php">winxp-fastswitch-account-lockout(7731)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3717">3717</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1571" seq="2001-1571" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-12/0213.html">20011220 Windows XP security concerns</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7732.php">winxp-remote-desktop-username(7732)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3720">3720</ref>
    </refs>
    <vuln_soft>
      <prod name="windows_xp" vendor="microsoft">
        <vers num="" edition=":home"/>
        <vers num="" edition="gold:professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1572" seq="2001-1572" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-10/0057.html" adv="1" patch="1">20011008 Bug in Linux 2.4 / iptables MAC match module</ref>
      <ref source="XF" url="http://www.iss.net/security_center/static/7267.php">linux-netfilter-bypass-filter(7267)</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3418" patch="1">3418</ref>
    </refs>
    <vuln_soft>
      <prod name="linux_kernel" vendor="linux">
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1573" seq="2001-1573" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in smtpscan.dll for Trend Micro InterScan VirusWall 3.51 for Windows NT has allows remote attackers to execute arbitrary code via a certain configuration parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00407.html" adv="1" patch="1">20010628 [SNS Advisory No.34] TrendMicro InterScan VirusWall 3.51 smtpscan.dll Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.51" edition=":windows_nt"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1574" seq="2001-1574" published="2001-12-31" modified="2008-09-05" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in (1) HttpSaveCVP.dll and (2) HttpSaveCSP.dll in Trend Micro InterScan VirusWall 3.5.1 allows remote attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00408.html" adv="1" patch="1">20010628 [SNS Advisory No.35] TrendMicro InterScan VirusWall 3.51 HttpSaveC*P.dll Buffer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod name="interscan_viruswall" vendor="trend_micro">
        <vers num="3.5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1575" seq="2001-1575" published="2001-12-31" modified="2017-07-10" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">Apple Personal Web Sharing (PWS) 1.1, 1.5, and 1.5.5, when Web Sharing authentication is enabled, allows remote attackers to cause a denial of service via a long password, possibly due to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00409.html">20010628 MacOS Personal Wed Sharing DoS</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2945">2945</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6759">macos-personal-web-sharing-dos(6759)</ref>
    </refs>
    <vuln_soft>
      <prod name="personal_web_sharing" vendor="apple">
        <vers num="1.1"/>
        <vers num="1.5"/>
        <vers num="1.5.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1576" seq="2001-1576" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="4.6" CVSS_base_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Buffer overflow in cron in Caldera UnixWare 7 allows local users to execute arbitrary code via a command line argument.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00404.html" adv="1" patch="1">CSSA-2001-SCO.3</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="caldera">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1577" seq="2001-1577" published="2001-12-31" modified="2017-07-10" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">Unknown vulnerability in CDE in Caldera OpenUnix 7.1.0, 7.1.1, and 8.0 allows an xterm session to gain privileges when the session is reused.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q4/0017.html" adv="1" patch="1">CSSA-2001-SCO.37</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3646" patch="1">3646</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7666">cde-xterm-gain-privileges(7666)</ref>
    </refs>
    <vuln_soft>
      <prod name="unixware" vendor="caldera">
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
      </prod>
      <prod name="openunix" vendor="caldera">
        <vers num="8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1578" seq="2001-1578" published="2001-12-31" modified="2008-09-05" severity="Low" CVSS_version="2.0" CVSS_score="2.1" CVSS_base_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)">
    <desc>
      <descript source="cve">Unknown vulnerability in SCO OpenServer 5.0.6 and earlier allows local users to modify critical information such as certain CPU registers and segment descriptors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q4/0014.html" adv="1" patch="1">CSSA-2001-SCO.35</ref>
    </refs>
    <vuln_soft>
      <prod name="openserver" vendor="sco">
        <vers num="5.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1579" seq="2001-1579" published="2001-12-31" modified="2008-09-05" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)">
    <desc>
      <descript source="cve">The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, which allows remote attackers to cause a denial of service.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="CALDERA" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q4/0020.html" adv="1" patch="1">CSSA-2001-SCO.39</ref>
    </refs>
    <vuln_soft>
      <prod name="open_unix" vendor="sco">
        <vers num="8.0.0"/>
      </prod>
      <prod name="unixware" vendor="sco">
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1580" seq="2001-1580" published="2001-12-31" modified="2017-12-18" severity="Medium" CVSS_version="2.0" CVSS_score="5.0" CVSS_base_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-12/0204.html" adv="1">20011219 IRM Security Advisory 002: Netware Web Server Source Disclosure</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-12/0218.html">20011220 Re: IRM Security Advisory 002: Netware Web Server Source Disclosure</ref>
      <ref source="BUGTRAQ" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2001-12/0221.html">20011220 Re: IRM Security Advisory 002: Netware Web Server Source Disclosure</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3715" patch="1">3715</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7726">netware-webserver-directory-traversal(7726)</ref>
    </refs>
    <vuln_soft>
      <prod name="scriptease_webserver" vendor="nombas">
        <vers num="4.30b"/>
        <vers num="4.30d"/>
      </prod>
      <prod name="netware" vendor="novell">
        <vers num="5.1" edition="sp2a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1581" seq="2001-1581" published="2001-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">The File Blocker feature in Clearswift MAILsweeper for SMTP 4.2 allows remote attackers to bypass e-mail attachment filtering policies via a modified name in a Content-Type header.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.mimesweeper.com/support/technotes/notes/1102.asp">http://www.mimesweeper.com/support/technotes/notes/1102.asp</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6801">mailsweeper-bypass-file-blocker(6801)</ref>
    </refs>
    <vuln_soft>
      <prod name="mailsweeper" vendor="clearswift_limited">
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1582" seq="2001-1582" published="2001-12-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="7.2" CVSS_base_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary code via a long LDAP_OPTIONS environment variable to a privileged program that uses libsldap.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jul/0077.html">20010705 Solaris 8 libsldap exploit</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jul/0091.html">20010706 Re: Solaris 8 libsldap exploit</ref>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jun/0365.html">20010626 Solaris 8 libsldap buffer overflow</ref>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/5IP0O2A4KS.html">http://www.securiteam.com/unixfocus/5IP0O2A4KS.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/2931" patch="1">2931</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="8.0" edition="unkown:x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1583" seq="2001-1583" published="2001-12-31" modified="2018-10-30" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=99929694701826&amp;w=2">20010831 Solaris LPD Exploit (fwd)</ref>
      <ref source="MISC" url="http://metasploit.com/projects/Framework/modules/exploits/solaris_lpd_exec.pm">http://metasploit.com/projects/Framework/modules/exploits/solaris_lpd_exec.pm</ref>
      <ref source="SF-INCIDENTS" url="http://www.derkeiler.com/Mailing-Lists/securityfocus/incidents/2001-08/0490.html">20010829 solaris lpd, KARMAPOLICE?</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3274">3274</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7087">solaris-lpd-sendmail-commands(7087)</ref>
    </refs>
    <vuln_soft>
      <prod name="solaris" vendor="sun">
        <vers num="2.4" edition=":x86"/>
        <vers num="2.5" edition=":x86"/>
        <vers num="2.5.1" edition=":x86"/>
        <vers num="2.6"/>
        <vers num="7.0" edition=":x86"/>
        <vers num="8.0" edition="unkown:x86"/>
      </prod>
      <prod name="sunos" vendor="sun">
        <vers num="-"/>
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.4"/>
        <vers num="5.5"/>
        <vers num="5.5.1"/>
        <vers num="5.7"/>
        <vers num="5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1584" seq="2001-1584" published="2001-12-31" modified="2017-07-28" severity="High" CVSS_version="2.0" CVSS_score="7.5" CVSS_base_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">CardBoard 2.4 greeting card CGI by Michael Barretto allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="MISC" url="http://www.securiteam.com/unixfocus/5MP0M2K5FC.html">http://www.securiteam.com/unixfocus/5MP0M2K5FC.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3360">3360</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/7178">cardboard-recipient-command-execution(7178)</ref>
    </refs>
    <vuln_soft>
      <prod name="cardboard" vendor="michael_barretto">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1585" seq="2001-1585" published="2001-12-31" modified="2017-07-28" severity="Medium" CVSS_version="2.0" CVSS_score="6.8" CVSS_base_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)">
    <desc>
      <descript source="cve">SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by supplying a public key from that user's authorized_keys file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0159.html">20010208 Authentication By-Pass Vulnerability in OpenSSH-2.3.1 (devel snapshot)</ref>
      <ref source="BID" url="http://online.securityfocus.com/bid/2356" patch="1">2356</ref>
      <ref source="CONFIRM" url="http://www.openbsd.org/advisories/ssh_bypass.txt" patch="1">http://www.openbsd.org/advisories/ssh_bypass.txt</ref>
      <ref source="XF" url="https://exchange.xforce.ibmcloud.com/vulnerabilities/6084">openssh-bypass-authentication(6084)</ref>
    </refs>
    <vuln_soft>
      <prod name="openssh" vendor="openbsd">
        <vers num="2.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" name="CVE-2001-1586" seq="2001-1586" published="2010-02-12" modified="2017-08-16" severity="High" CVSS_version="2.0" CVSS_score="10.0" CVSS_base_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)">
    <desc>
      <descript source="cve">Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2001/Jul/660">20010727 SimpleServer:WWW Command Execution Vulnerability Exploit Code Released</ref>
      <ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
      <ref source="MISC" url="http://www.securiteam.com/windowsntfocus/5TP0B1P4UK.html">http://www.securiteam.com/windowsntfocus/5TP0B1P4UK.html</ref>
      <ref source="BID" url="http://www.securityfocus.com/bid/3112">3112</ref>
      <ref source="XF" url="https://exc